CVE-2025-48640: High severity Google Android vulnerability
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable and enforce permission checks and explicit user confirmation for third-party passkey entry / pairing approvals so that pairing cannot be completed without an approval decision and visible user interaction.
Passkey pairing / passkey entry approval permission_check_and_user_confirmation = enabled - Compensating control
Restrict proximity/adjacent pairing interfaces (e.g., Bluetooth/NFC/wireless pairing endpoints) to trusted networks/devices and limit or block 3rd‑party app ability to initiate or approve passkey entry/pairing. Apply network/firewall controls or device management policies to prevent untrusted devices from connecting.
- Operational
Audit existing paired devices and remove any unrecognized or unauthorized pairings; monitor logs for unexpected pairing attempts and privilege-escalation indicators, and investigate/contain any suspicious activity.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48640?
CVE-2025-48640 has a risk score of 65, indicating a moderate severity level.
What types of systems are affected by CVE-2025-48640?
CVE-2025-48640 affects systems that allow third-party passkey entry pairing without proper permission checks.
How can I fix CVE-2025-48640?
To mitigate CVE-2025-48640, ensure that proper permission checks are implemented in your passkey entry pairing process.
What are the potential impacts of exploiting CVE-2025-48640?
Exploitation of CVE-2025-48640 can lead to remote escalation of privilege without requiring additional execution privileges.
Is user interaction required to exploit CVE-2025-48640?
No, user interaction is not required for the exploitation of CVE-2025-48640.