CVE-2025-48596: High severity Google Android vulnerability
In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48596?
CVE-2025-48596 is classified as a moderate severity vulnerability due to the potential for local escalation of privilege.
What does CVE-2025-48596 affect?
CVE-2025-48596 affects specific versions of Google Android, including 13.0, 14.0, 15.0, and 16.0.
How do I fix CVE-2025-48596?
To fix CVE-2025-48596, users are advised to update their Android devices to the latest security patches provided by Google.
Is user interaction required for exploiting CVE-2025-48596?
No, user interaction is not needed for exploiting CVE-2025-48596, making it a significant concern.
What does CVE-2025-48596 entail?
CVE-2025-48596 involves an out of bounds read in the appendFrom function of Parcel.cpp due to a missing bounds check.