CVE-2025-22423

All FrameworksAndroidCWE-125CVE-2025-22423

CVE-2025-22423

State: PUBLISHED · Published: 2025-09-02 · Updated: 2025-09-03 · Assigner: google_android
Description
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/22xxx/CVE-2025-22423.json