HomeDefault status
unaffected
16
affected
15
affected
14
affected
13
affected
Description
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Information disclosure
Product status
16
15
14
13
References
android.googlesource.com/...9252c80b0edf7f4ae282bce4579410ad
source.android.com/security/bulletin/2025-09-01