Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-8192— Race condition in AndroidTV TvSettings

Quick assessment

Affected
Android TV
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Android TV是美国谷歌(Google)公司的一个电视操作系统应用。 Google Android TV存在安全漏洞,该漏洞源于TOCTOU竞争条件,可能导致任意活动启动。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.10% · P1
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-8192

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Race condition in AndroidTV TvSettings
Source: CVE Program / CVE List V5
Vulnerability Description
There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
Google Android TV 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Android TV是美国谷歌(Google)公司的一个电视操作系统应用。 Google Android TV存在安全漏洞,该漏洞源于TOCTOU竞争条件,可能导致任意活动启动。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Android TV 0 -

II. Public POCs for CVE-2025-8192

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-8192

请登录查看更多情报信息。

Other References for CVE-2025-8192 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-8192

No comments yet


Leave a comment