VYPR

Talkback

by Google

CVEs (1)

  • CVE-2025-26439HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic error in the code. This could lead to local escalation of privilege with no additional execution…