CVE-2025-0077 Details
Description
In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
A race condition vulnerability has been identified in the UserController component of the Android framework. This issue allows for a lock screen bypass, potentially leading to unauthorized access to privileged operations. The vulnerability exists in multiple versions of the Android framework, specifically within the UserController.java file, and can be exploited without any additional permissions or user interaction.
Users can update to the latest version of Android to address this vulnerability. Instructions for checking and updating the Android version are available on the Google Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1223 | Race Condition for Write-Once Attributes | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 15.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | Initial Analysis | [email protected] |
| Sep 4, 2025 | CVE Modified | CISA-ADP |
| Sep 4, 2025 | New CVE Received | [email protected] |