There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function.
History

Thu, 31 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Android
Android android
Android tv
Google
Google android Tv
Vendors & Products Android
Android android
Android tv
Google
Google android Tv

Thu, 31 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 08:45:00 +0000

Type Values Removed Values Added
Description There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function.
Title Race condition in AndroidTV TvSettings
Weaknesses CWE-367
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2025-07-31T08:24:26.612Z

Updated: 2025-07-31T13:20:16.832Z

Reserved: 2025-07-25T08:57:20.782Z

Link: CVE-2025-8192

cve-icon Vulnrichment

Updated: 2025-07-31T13:20:12.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T09:15:27.827

Modified: 2025-07-31T18:42:37.870

Link: CVE-2025-8192

cve-icon Redhat

No data.