On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly implemented.
Due to this misconfiguration, an attacker capable of invoking an Android intent can exploit this vulnerability to send messages on the user’s behalf to arbitrary receivers without requiring any further user interaction or specific permissions. This allows for the silent and unauthorized transmission of messages from a compromised Wear OS device.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://towerofhanoi.it/writeups/cve-2025-12080/ |
|
History
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Google wear Os |
|
| Vendors & Products |
Google
Google android Google wear Os |
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly implemented. Due to this misconfiguration, an attacker capable of invoking an Android intent can exploit this vulnerability to send messages on the user’s behalf to arbitrary receivers without requiring any further user interaction or specific permissions. This allows for the silent and unauthorized transmission of messages from a compromised Wear OS device. | |
| Title | Intent Abuse in Google Messages for Wear OS for Silent Message Sending | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published: 2025-10-27T08:45:52.604Z
Updated: 2025-10-27T15:53:29.322Z
Reserved: 2025-10-22T15:24:43.272Z
Link: CVE-2025-12080
Updated: 2025-10-27T15:53:21.803Z
Status : Awaiting Analysis
Published: 2025-10-27T09:15:36.040
Modified: 2025-10-27T13:19:49.063
Link: CVE-2025-12080
No data.