CVE-2025-48609: Path Traversal
In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48609?
CVE-2025-48609 has a medium severity level due to its potential to cause local denial of service.
How do I fix CVE-2025-48609?
To mitigate CVE-2025-48609, update to the latest patched version of the affected Android OS.
Which versions of Android are affected by CVE-2025-48609?
CVE-2025-48609 affects Android versions 14.0, 15.0, and 16.0.
What are the potential impacts of CVE-2025-48609?
The potential impacts of CVE-2025-48609 include arbitrary file deletion affecting telephony, SMS, and MMS functionalities.
Is user interaction required to exploit CVE-2025-48609?
No, user interaction is not needed to exploit CVE-2025-48609.