CVE-2025-48528: Medium severity Google Android vulnerability
In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48528?
CVE-2025-48528 is rated as a critical vulnerability due to the potential for local privilege escalation through tapjacking attacks.
How do I fix CVE-2025-48528?
To fix CVE-2025-48528, update the affected Android device to the latest security patch provided by the vendor.
What types of devices are affected by CVE-2025-48528?
CVE-2025-48528 affects devices running the Google Android operating system.
Is user interaction required to exploit CVE-2025-48528?
No, exploitation of CVE-2025-48528 does not require user interaction, making it particularly concerning.
What potential impacts does CVE-2025-48528 have on affected devices?
CVE-2025-48528 could allow attackers to perform unauthorized actions by gaining elevated privileges on the affected devices.