CVE-2025-48525: Input Validation
In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated to a companion device due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48525?
CVE-2025-48525 has a medium severity rating due to the potential for local escalation of privilege.
How do I fix CVE-2025-48525?
To fix CVE-2025-48525, ensure that your device is updated to the latest version of Google Android, specifically the patched versions beyond 16.0.
What products are affected by CVE-2025-48525?
CVE-2025-48525 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
What is the nature of the vulnerability in CVE-2025-48525?
CVE-2025-48525 relates to improper input validation in DisassociationProcessor.java, allowing reading notifications when not associated with a companion device.
Can CVE-2025-48525 be exploited without authentication?
Yes, CVE-2025-48525 can be exploited with no additional execution privileges needed.