CVE-2025-48592: Buffer Overflow
Published Dec 1, 2025
·Updated
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
3 affected components
Google Android
Google Android=15.0
Google Android=16.0
Remediation
Event History
Dec 1, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
Affected Software
Dec 8, 2025
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48592?
CVE-2025-48592 has a high severity rating due to the potential for remote information disclosure.
2
How do I fix CVE-2025-48592?
To fix CVE-2025-48592, update your Android device to the latest security patch provided by Google.
3
Which versions of Android are affected by CVE-2025-48592?
CVE-2025-48592 affects Google Android versions 15.0 and 16.0.
4
What is the impact of CVE-2025-48592?
The impact of CVE-2025-48592 includes possible out of bounds reads due to a heap buffer overflow.
5
Is user interaction required to exploit CVE-2025-48592?
No, user interaction is not needed for exploitation of CVE-2025-48592.