{"id":"CVE-2025-32347","title":"In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent","summary":"In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. U…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-926"],"vendor":"google","product":"android","affected":["android = 13.0","android = 14.0","android = 15.0","android = 16.0"],"published":"2025-09-04","updated":"2026-10-01","sourceUpdated":"2026-10-01T16:10:00.257","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-32347","references":[{"url":"https://android.googlesource.com/platform/packages/apps/Settings/+/25cfacbe5ac2423b8fe1375e0593ef69e98b8d09","label":"security@android.com"},{"url":"https://source.android.com/security/bulletin/2025-09-01","label":"security@android.com"}],"tags":["nvd"],"epss":0.00086,"epssPercentile":0.00312,"ingestedAt":"2026-10-01T18:55:42.282Z","slug":"CVE-2025-32347","body":"## Overview\n\nIn onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.\n\n## Affected\n\n- `android = 13.0`\n- `android = 14.0`\n- `android = 15.0`\n- `android = 16.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}