CVE-2025-48590: Medium severity Google Android vulnerability
In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48590?
CVE-2025-48590 is classified as a local denial of service vulnerability.
How do I fix CVE-2025-48590?
To mitigate CVE-2025-48590, update your Android device to the latest version provided by Google.
Which Android versions are affected by CVE-2025-48590?
CVE-2025-48590 affects Android versions 13.0, 14.0, 15.0, and 16.0.
What does CVE-2025-48590 allow a malicious app to do?
CVE-2025-48590 allows a malicious app to potentially prevent dialing emergency services under specific conditions.
Is user interaction required for CVE-2025-48590 to be exploited?
No, user interaction is not required for the exploitation of CVE-2025-48590.