Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-31931. PoCs published by yohanes.
AI-analyzed exploit summary This PoC demonstrates CVE-2025-31931, an arbitrary shared library loading vulnerability in the Intel ITT API on Android, affecting OpenCV 4.10. The exploit loads a malicious library via a constructor function, sending notifications via Telegram and displaying a toast message.
Description
Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Exploits (1)
This PoC demonstrates CVE-2025-31931, an arbitrary shared library loading vulnerability in the Intel ITT API on Android, affecting OpenCV 4.10. The exploit loads a malicious library via a constructor function, sending notifications via Telegram and displaying a toast message.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H