CVE-2025-20899
CVSS 3.1 Score 4 of 10 (medium)
Details
Published Feb 4, 2025
Summary
CVE-2025-20899 is a critical access control vulnerability affecting PushNotification prior to versions 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14. This issue enables local attackers to bypass access controls and gain unauthorized access to sensitive information on these Android operating systems. The vulnerability may lead to data theft or further system compromise. Users are strongly advised to update their PushNotification and Android OS to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share