PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-0425 Google CVE debrief

CVE-2017-0425 is an Android information disclosure issue in Audioserver. According to the vendor and NVD records, a local malicious application could access data outside its permission levels, creating a confidentiality risk without requiring code execution. The CVE was published on 2017-02-08, and Android’s security bulletin for 2017-02-01 is the vendor reference associated with the fix.

Vendor
Google
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-08
Original CVE updated
2026-05-13
Advisory published
2017-02-08
Advisory updated
2026-05-13

Who should care

Android platform maintainers, OEM patch teams, mobile device administrators, app security reviewers, and defenders responsible for devices running affected Android versions.

Technical summary

NVD classifies the issue as CVSS 3.0 5.5 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) and CWE-200. The vulnerability affects Audioserver and may allow a local malicious app to read information it should not be able to access. The issue is described as affecting Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.1 in the supplied record.

Defensive priority

Medium. The issue is locally exploitable and requires user interaction, but it can expose sensitive data with high confidentiality impact. Prioritize it on devices that permit untrusted app installation or that handle sensitive media-related data.

Recommended defensive actions

  • Apply the Android security bulletin fixes referenced for the 2017-02-01 update cycle.
  • Verify fleet coverage for the affected Android versions listed in the record: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, and 7.1.1.
  • Treat this as a confidentiality issue and review whether local app execution is possible on managed devices.
  • Restrict installation of untrusted applications and enforce mobile application control where practical.
  • Monitor vendor advisories and device OEM patch status to confirm the remediation is present on deployed builds.

Evidence notes

This debrief is based only on the supplied NVD record and the linked Android security bulletin. The record states an information disclosure in Audioserver, local malicious-app access beyond permission levels, CWE-200, and CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. Published date context comes from the CVE record (2017-02-08) and the vendor bulletin reference dated 2017-02-01.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-0425 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-0425

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-0425 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0425

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.