In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
History

Fri, 05 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Thu, 04 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 04 Sep 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Thu, 04 Sep 2025 05:30:00 +0000

Type Values Removed Values Added
Description In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published: 2025-09-04T05:17:19.856Z

Updated: 2025-09-05T03:55:32.940Z

Reserved: 2025-04-16T00:33:09.030Z

Link: CVE-2025-36887

cve-icon Vulnrichment

Updated: 2025-09-04T13:13:52.173Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-04T10:42:29.183

Modified: 2025-09-05T16:39:25.790

Link: CVE-2025-36887

cve-icon Redhat

No data.