CVE-2025-48599: High severity Google Android vulnerability
In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48599?
The severity of CVE-2025-48599 is classified as high due to the potential for local escalation of privilege.
How do I fix CVE-2025-48599?
To fix CVE-2025-48599, update your Android device to version 14.0 or higher where the vulnerability is addressed.
What devices are affected by CVE-2025-48599?
CVE-2025-48599 affects devices running Android versions 13.0 and 14.0.
Is user interaction required to exploit CVE-2025-48599?
No, user interaction is not needed for the exploitation of CVE-2025-48599.
What kind of vulnerability is CVE-2025-48599?
CVE-2025-48599 is a local escalation of privilege vulnerability due to a missing permission check.