CVE-2025-48621: High severity Google Android vulnerability
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48621?
CVE-2025-48621 is classified as a medium severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2025-48621?
To mitigate CVE-2025-48621, users should update their Android devices to the latest version provided by Google.
What types of devices are affected by CVE-2025-48621?
CVE-2025-48621 affects Google Android devices running versions 13.0 through 16.0.
Is user interaction required for exploiting CVE-2025-48621?
Yes, CVE-2025-48621 requires user interaction for exploitation to enable a tapjacking attack.
What is the potential impact of CVE-2025-48621?
The potential impact of CVE-2025-48621 is local privilege escalation with no additional execution permissions needed.