CVE-2025-48614: Medium severity Google Android vulnerability
In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This could lead to physical denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48614?
The severity of CVE-2025-48614 is considered high due to its potential for physical denial of service.
How do I fix CVE-2025-48614?
To fix CVE-2025-48614, update your device to the latest version of Android that includes the security patch.
Which Android versions are affected by CVE-2025-48614?
CVE-2025-48614 affects Android versions 13.0, 14.0, 15.0, and 16.0.
What type of attack does CVE-2025-48614 enable?
CVE-2025-48614 enables a physical denial of service attack by allowing unauthorized factory resets.
Is user interaction required to exploit CVE-2025-48614?
No, user interaction is not required to exploit CVE-2025-48614, making it a greater risk.