{"id":"ASB-A-383328827","details":"In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-383328827","CVE-2025-26422"],"modified":"2026-04-17T15:55:28.020024Z","published":"2025-05-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2025-05-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/63ae789499395abc2b71fd46f57cac3c4ba1bd9d"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2025-05-01"}]}],"versions":["15"],"ecosystem_specific":{"vanir_signatures":[{"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/c617d697cdbef000cb416aefc08fc4a3cda4afa1","target":{"file":"services/core/java/com/android/server/wm/WindowManagerService.java"},"digest":{"threshold":0.9,"line_hashes":["307962230069551633409797844037804565870","195435758164607766111867084465255626687","100459581530201667367539293380375120994","65869109269366220216044413136000641265","150808033846765711730010162772074374039","49229083276072875436173481827860330314","263569157269227770725311902885171890912","8045441567988998432299067648344290672","260420910750437969770877208474464448596"]},"signature_version":"v1","match_only_versions":["15"],"signature_type":"Line","id":"ASB-A-383328827-19a066d0"},{"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/c617d697cdbef000cb416aefc08fc4a3cda4afa1","exact_target_file_match_only":true,"target":{"function":"dump","file":"services/core/java/com/android/server/wm/WindowManagerService.java"},"digest":{"function_hash":"65039974368923320334274338561678664778","length":132},"signature_version":"v1","match_only_versions":["15"],"signature_type":"Function","id":"ASB-A-383328827-5aa2292d"},{"digest":{"function_hash":"245006804470477077414571673338369743527","length":5658},"deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/base/+/c617d697cdbef000cb416aefc08fc4a3cda4afa1","target":{"function":"doDump","file":"services/core/java/com/android/server/wm/WindowManagerService.java"},"signature_type":"Function","id":"ASB-A-383328827-762d9c41","signature_version":"v1"}],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/c617d697cdbef000cb416aefc08fc4a3cda4afa1"],"types":["EoP"],"spl":"2025-05-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-383328827.json"}}],"schema_version":"1.7.5"}