CVE-2025-48612: Input Validation
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48612?
CVE-2025-48612 has a high severity rating due to the potential for local escalation of privilege affecting multiple Android versions.
How do I fix CVE-2025-48612?
To fix CVE-2025-48612, users should update their Google Android devices to the latest security patches available.
Which versions of Google Android are affected by CVE-2025-48612?
CVE-2025-48612 affects Google Android versions 13.0, 14.0, 15.0, and 16.0.
What kind of vulnerability is CVE-2025-48612?
CVE-2025-48612 is a vulnerability that allows unauthorized modification of the default NFC payment settings through improper input validation.
Is user interaction required to exploit CVE-2025-48612?
No, CVE-2025-48612 can be exploited without any user interaction needed.