In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
https://thehackernews.com/2025/09/samsung-fixes-critical-zero-day-cve.html
https://www.securityweek.com/two-exploited-vulnerabilities-patched-in-android/
https://www.theregister.com/2025/09/03/android_patch_september/
https://thehackernews.com/2025/09/android-security-alert-google-patches.html
https://cyberscoop.com/android-security-update-september-2025/