CVE-2025-48623: Input Validation
In initpkvmhypvcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48623?
CVE-2025-48623 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
How does CVE-2025-48623 affect Google Android?
CVE-2025-48623 affects Google Android by allowing an out of bounds write that can result in local escalation of privilege.
How do I fix CVE-2025-48623?
To fix CVE-2025-48623, ensure that your Google Android device is updated with the latest security patches provided by Google.
Who is impacted by CVE-2025-48623?
CVE-2025-48623 impacts users of Google Android devices that do not have the latest security updates installed.
Is user interaction required to exploit CVE-2025-48623?
No, user interaction is not required to exploit CVE-2025-48623, making it particularly concerning for affected systems.