CVE-2025-48624: Input Validation
Published Dec 1, 2025
·Updated
In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Google Android
Google Android
Event History
Dec 1, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
Affected Software
Dec 2, 2025
News Published
via The Register·06:47 PM
News Published
via The Register·06:52 PM
Dec 8, 2025
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48624?
CVE-2025-48624 has a high severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2025-48624?
To fix CVE-2025-48624, update your Android device to the latest security patch released by Google.
3
Who is affected by CVE-2025-48624?
CVE-2025-48624 affects devices running vulnerable versions of Google Android.
4
What are the risks associated with CVE-2025-48624?
The primary risk of CVE-2025-48624 is the potential for an attacker to gain elevated privileges on a vulnerable device.
5
Is user interaction required to exploit CVE-2025-48624?
No, user interaction is not needed for exploitation of CVE-2025-48624.