CVE-2025-48591: Medium severity Google Android vulnerability
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48591?
CVE-2025-48591 is classified as a medium severity vulnerability due to its potential for local information disclosure.
How do I fix CVE-2025-48591?
To fix CVE-2025-48591, update your Google Android device to the latest version available that addresses this vulnerability.
What types of devices are affected by CVE-2025-48591?
CVE-2025-48591 affects Google Android devices running versions 13.0, 14.0, and 15.0.
What can an attacker do with CVE-2025-48591?
An attacker can exploit CVE-2025-48591 to read files belonging to other users, leading to potential information disclosure.
Is user interaction required to exploit CVE-2025-48591?
No, user interaction is not needed for the exploitation of CVE-2025-48591.