CVE-2025-48602: High severity Google Android vulnerability
Published Mar 2, 2026
·Updated
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Mar 2, 2026
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is locally exploitable with no privileges and requires no user interaction. It could enable escalation of privilege through a lockscreen bypass.
2
What impact could successful exploitation have?
Successful exploitation could allow a local attacker to bypass the lockscreen and gain high confidentiality, integrity, and availability impact, according to the CVSS vector.