CVE-2025-48548: Race Condition
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48548?
CVE-2025-48548 has a moderate severity level due to its potential for local escalation of privilege.
How do I fix CVE-2025-48548?
To fix CVE-2025-48548, ensure that your Android device is updated to the latest security patch provided by Google.
What are the potential impacts of CVE-2025-48548?
CVE-2025-48548 could allow an attacker to record audio without user consent, violating privacy.
Who is affected by CVE-2025-48548?
CVE-2025-48548 affects users of specific versions of Google Android that include the vulnerable AppOpsControllerImpl.java functions.
Is user interaction required for exploiting CVE-2025-48548?
Yes, exploitation of CVE-2025-48548 requires user interaction to trigger the vulnerability.