CVE-2025-48618: Medium severity Google Android vulnerability
In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48618?
CVE-2025-48618 is considered a high severity vulnerability due to the potential for physical escalation of privilege.
How do I fix CVE-2025-48618?
To address CVE-2025-48618, ensure your Android device is updated to the latest version available from the manufacturer.
What versions of Android are affected by CVE-2025-48618?
CVE-2025-48618 affects Android versions 13.0, 14.0, 15.0, and 16.0.
Can CVE-2025-48618 be exploited without user interaction?
Yes, CVE-2025-48618 can be exploited without any user interaction required.
What does CVE-2025-48618 impact in terms of device security?
CVE-2025-48618 can lead to unauthorized interaction through the lockscreen, posing a significant security risk.