In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
https://source.android.com/security/bulletin/2025-04-01
https://android.googlesource.com/platform/packages/providers/MediaProvider/+/961c8cbd2a489277876aeffa40ebdee5eae29f1f
Source: Mitre, NVD
Published: 2025-09-02
Updated: 2025-09-04
Base Score: 4.6
Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00009