In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

cve CVE-2025-26431 1 source, 1 claim · Watch

NVD writes:
In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No… the claim

What it is to other things

affectsgoogle/android
NVD
made_bygoogle
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-26431",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-26431",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-09T03:55:18.722098Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-09-04T20:15:36.447",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Broken Link"
        ],
        "url": "https://source.android.com/security/bulletin/wear/2025-05-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-693"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDAndroid
receipt
Source
NVD
Its words
Android
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-26431",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-26431",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-09T03:55:18.722098Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-09-04T20:15:36.447",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Broken Link"
        ],
        "url": "https://source.android.com/security/bulletin/wear/2025-05-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-693"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-26431",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-26431",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-09T03:55:18.722098Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-09-04T20:15:36.447",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Broken Link"
        ],
        "url": "https://source.android.com/security/bulletin/wear/2025-05-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-693"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGoogle
receipt
Source
NVD
Its words
Google
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "14"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-26431",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-26431",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-09-09T03:55:18.722098Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-09-04T20:15:36.447",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Broken Link"
        ],
        "url": "https://source.android.com/security/bulletin/wear/2025-05-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-693"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
zetlyn/cve-nvd · 2025-09-04
cvss 7.8 product Android status Analyzed vendor Google source