CVE-2025-48545: High severity Google Android vulnerability
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48545?
CVE-2025-48545 is classified as a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2025-48545?
To fix CVE-2025-48545, update your affected Android device to the latest security patch provided by Google.
Who is affected by CVE-2025-48545?
CVE-2025-48545 affects users of Google Android operating systems that have not been updated to include the security patch.
What are the impacts of CVE-2025-48545?
The impact of CVE-2025-48545 includes unauthorized access to privileged APIs, potentially allowing apps to escalate their privileges without user interaction.
Is user interaction required to exploit CVE-2025-48545?
No, user interaction is not required to exploit CVE-2025-48545, making it a more concerning vulnerability.