PatchSiren cyber security CVE debrief
CVE-2017-0425 Google CVE debrief
CVE-2017-0425 is an Android information disclosure issue in Audioserver. According to the vendor and NVD records, a local malicious application could access data outside its permission levels, creating a confidentiality risk without requiring code execution. The CVE was published on 2017-02-08, and Android’s security bulletin for 2017-02-01 is the vendor reference associated with the fix.
- Vendor
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-08
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-08
- Advisory updated
- 2026-05-13
Who should care
Android platform maintainers, OEM patch teams, mobile device administrators, app security reviewers, and defenders responsible for devices running affected Android versions.
Technical summary
NVD classifies the issue as CVSS 3.0 5.5 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) and CWE-200. The vulnerability affects Audioserver and may allow a local malicious app to read information it should not be able to access. The issue is described as affecting Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.1 in the supplied record.
Defensive priority
Medium. The issue is locally exploitable and requires user interaction, but it can expose sensitive data with high confidentiality impact. Prioritize it on devices that permit untrusted app installation or that handle sensitive media-related data.
Recommended defensive actions
- Apply the Android security bulletin fixes referenced for the 2017-02-01 update cycle.
- Verify fleet coverage for the affected Android versions listed in the record: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.1.
- Treat this as a confidentiality issue and review whether local app execution is possible on managed devices.
- Restrict installation of untrusted applications and enforce mobile application control where practical.
- Monitor vendor advisories and device OEM patch status to confirm the remediation is present on deployed builds.
Evidence notes
This debrief is based only on the supplied NVD record and the linked Android security bulletin. The record states an information disclosure in Audioserver, local malicious-app access beyond permission levels, CWE-200, and CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. Published date context comes from the CVE record (2017-02-08) and the vendor bulletin reference dated 2017-02-01.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0425 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0425
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0425 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0425
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://source.android.com/security/bulletin/2017-02-01.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.