CVE-2025-48594: Input Validation
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48594?
CVE-2025-48594 is classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2025-48594?
To mitigate CVE-2025-48594, ensure that your Android version is updated to a patched release provided by Google.
What is the impact of CVE-2025-48594?
The impact of CVE-2025-48594 allows an attacker to retain privileges after disassociation, leading to potential unauthorized access.
Which versions of Android are affected by CVE-2025-48594?
CVE-2025-48594 affects Google Android versions 14.0, 15.0, and 16.0.
Is user interaction required for CVE-2025-48594 exploitation?
Yes, user interaction is needed for the exploitation of CVE-2025-48594.