CVE-2025-48573: High severity Google Android vulnerability
In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due to FGS while-in-use abuse. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48573?
CVE-2025-48573 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2025-48573?
To fix CVE-2025-48573, update your Android device to the latest version provided by Google.
Which versions of Android are affected by CVE-2025-48573?
CVE-2025-48573 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
What are the risks associated with CVE-2025-48573?
The risks of CVE-2025-48573 include potential local escalation of privilege without user interaction.
Is user interaction required to exploit CVE-2025-48573?
No, user interaction is not needed to exploit CVE-2025-48573, making it more dangerous.