Back

HIGH

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation

Published Dec 8, 2025

Description

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner google_android
Published Dec 8, 2025
Updated Feb 26, 2026
Reserved May 22, 2025

CISA Vulnrichment

Updated Dec 9, 2025

NVD

Status Modified
Modified Oct 7, 2026

Red Hat

No data

ENISA EUVD

Assigner google_android
Published Dec 8, 2025
Updated Feb 26, 2026

GitHub

No data