CVE-2025-48606: High severity Google Android vulnerability
In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation without a mechanism to uninstall it due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48606?
The severity of CVE-2025-48606 is classified as high due to its potential for local escalation of privilege.
How do I fix CVE-2025-48606?
To fix CVE-2025-48606, ensure that you update to the latest version of Google Android that addresses this vulnerability.
What systems are affected by CVE-2025-48606?
CVE-2025-48606 affects Google Android version 16.0.
What are the potential risks associated with CVE-2025-48606?
The risks associated with CVE-2025-48606 include unauthorized access and control over applications that may become hidden without a proper uninstallation mechanism.
Is user interaction required to exploit CVE-2025-48606?
No, CVE-2025-48606 does not require additional user interaction to exploit the vulnerability.