CVE-2025-31710(google / android)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • s8000
  • sc9863a
  • t606

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
androids8000sc9863at606t612t616t750t760t765t770

4 versions affected across 13 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
By indicator
Full discourse1 post
  • Alex de la cruz@lexs17

    Project Qogirl6: Forensic Evidence of Longcheer Supply Chain Compromise Exploiting CVE-2025-31710 (cmd_skt) for Persistent Root and Multi-Channel Exfiltration https://github.com/rapid7/attackerkb/issues/87

    0000027
    198 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid13.0--
OSgoogleandroid14.0--
OSgoogleandroid15.0--
HWunisocs8000---
HWunisocsc9863a---
HWunisoct606---
HWunisoct612---
HWunisoct616---
HWunisoct750---
HWunisoct760---
HWunisoct765---
HWunisoct770---
HWunisoct820---
HWunisoct8300---
HWunisoct9300---

Explore more