There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Android
Android android Android tv Google android Tv |
|
Vendors & Products |
Android
Android android Android tv Google android Tv |
Thu, 31 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 31 Jul 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function. | |
Title | Race condition in AndroidTV TvSettings | |
Weaknesses | CWE-367 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Google
Published: 2025-07-31T08:24:26.612Z
Updated: 2025-07-31T13:20:16.832Z
Reserved: 2025-07-25T08:57:20.782Z
Link: CVE-2025-8192

Updated: 2025-07-31T13:20:12.620Z

Status : Awaiting Analysis
Published: 2025-07-31T09:15:27.827
Modified: 2025-07-31T18:42:37.870
Link: CVE-2025-8192

No data.