CVE-2025-31710
MEDIUMEngineerMode Service - Command Injection
Title source: llmDescription
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
Exploits (1)
Scores
CVSS v3
5.9
EPSS
0.0003
EPSS Percentile
7.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-77
Status
published
Products (3)
google/android
13.0
google/android
14.0
google/android
15.0
Published
Jun 03, 2025
Tracked Since
Feb 18, 2026