Skip to content

Instantly share code, notes, and snippets.

@krl5
Last active May 14, 2025 18:14
Show Gist options
  • Select an option

  • Save krl5/4eeed04a065287489c2e606e6d48c1bc to your computer and use it in GitHub Desktop.

Select an option

Save krl5/4eeed04a065287489c2e606e6d48c1bc to your computer and use it in GitHub Desktop.
CVE-2025-25370 – Lock Screen Privacy Bypass in realme GT 2 (RMX3311) with Android 14 / realme UI 5.0
CVE-2025-25370 – Lock Screen Privacy Bypass in realme GT 2 (RMX3311) with Android 14 / realme UI 5.0
Product: realme GT 2
Model: RMX3311
Operating System: Android 14
UI: realme UI 5.0
Software Version: RMX3311
Vulnerability Type: Privacy Violation / Lock Screen Bypass
CVE ID: CVE-2025-25370
Vulnerability Description
A privacy-related vulnerability exists in the realme GT 2 (RMX3311) running Android 14 with realme UI 5.0. The issue allows notification content (e.g., chat bubbles from Messenger) to be displayed on the lock screen, even when the privacy settings are configured to hide notification details. This occurs despite enabling the "Show app only" option in the lock screen notification settings.
This issue affects the device even when the user has set the privacy settings to prevent notification content from being visible on the lock screen.
Steps to Reproduce
1.Go to: Settings → Notifications & Status Bar → Lock Screen → Lock Screen Notifications → Show App Only
2.Lock the phone.
3.Perform one of the following actions available on the lock screen:
4.Swipe right to access the Wallpaper Carousel.
5.Use the camera shortcut (enabled by default).
6.Receive a message from a messenger that supports chat bubbles, such as Facebook Messenger.
7.Observe that the message content is displayed on the lock screen despite the device being locked.
Expected Behavior
Notification content should remain hidden on the lock screen unless the device is unlocked, in accordance with the user's privacy settings.
Impact
Critical privacy violation – allows unauthorized individuals to read private messages without unlocking the device.
Exploitation
An attacker must have physical access to the device with the lock screen enabled and the appropriate notification settings configured in order to exploit this vulnerability.
Disclosure Date
14th May 2025
Below are screenshots that confirm the described issue. You can view them by following the link below:
https://drive.google.com/drive/folders/1mdBSi0DD-TFzLUpJ1D4embgBGsbt22gC?usp=drive_link
Reporter
Karol Czubernat (czubernat.karol@gmail.com/krl99cz@gmail.com)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment