---
id: CVE-2025-22432
title: >-
  In notifyTimeout of CallRedirectionProcessor.java, there is a possible
  persistent connection due to improper input validation
summary: >-
  In notifyTimeout of CallRedirectionProcessor.java, there is a possible
  persistent connection due to improper input validation. This could lead to
  local escalation of privilege and background activity launches with User
  execution privileg…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: google
product: android
affected:
  - android = 13.0
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T17:10:00.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-22432'
references:
  - url: >-
      https://android.googlesource.com/platform/packages/services/Telecomm/+/a43a880beaa6a64348a1d0c821e8c7e98d741a79
    label: security@android.com
  - url: 'https://source.android.com/security/bulletin/2025-12-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00095
epssPercentile: 0.00615
ingestedAt: '2026-09-30T17:13:20.733Z'
---

## Overview

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 13.0`
- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
