CVE-2025-22442 is a local privilege escalation vulnerability in Android affecting DevicePolicyManagerService.java. A race condition in multiple functions can allow unauthorized applications to be installed into a newly created work profile. The flaw arises from improper synchronization during work profile creation and policy handling, creating a timing window in which application installation restrictions can be bypassed. Exploitation does not require user interaction and does not require additional execution privileges beyond local access on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit project for CVE-2025-22442 targeting Android work-profile provisioning. It contains 5 files total, but only one real code file: src/install_loop.py. The remaining files are documentation placeholders plus a top-level README that describes the research goal, attack flow, and claimed post-exploitation outcomes. The Python script is the operational core. It is a host-side automation tool that uses subprocess to invoke ADB on Windows, monitor connected Android devices, enumerate Android users, detect the appearance of a managed/work profile, and repeatedly attempt to install a specified APK into that profile using 'adb install --user'. It includes both a normal install path and a rapid retry loop intended to exploit a race/timing window during profile provisioning. Logging is written locally to exploit_installation_log.txt. Primary exploit capability: unauthorized APK injection into an Android managed/work profile during initialization. The code does not itself implement data theft or network exfiltration; instead, it deploys an APK payload that the README claims performs enterprise-data access and TCP-based exfiltration after installation. Therefore, the repository is best understood as an exploit orchestrator/dropper for payload deployment rather than a full end-to-end exfiltration implant. There are no hardcoded remote IPs, domains, or URLs in the code. The most fingerprintable artifacts are local Windows file paths for adb.exe and the APK, the local log file, and the ADB command strings used to interrogate the device and install the payload. The attack vector is primarily local/USB, requiring physical or proximate access to a device with ADB debugging enabled and a work-profile provisioning event in progress.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.