CVE-2025-48642: Infoleak
Published Mar 2, 2026
·Updated
In jumptopayload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android=14.0
Google Android=15.0
Google Android=16.0
Google Android=16.0-qpr2_beta_1
Google Android=16.0-qpr2_beta_2
Google Android=16.0-qpr2_beta_3
Event History
Mar 2, 2026
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48642?
The severity of CVE-2025-48642 is rated as medium due to local information disclosure risks.
2
How do I fix CVE-2025-48642?
To fix CVE-2025-48642, update to the latest version of Google Android that addresses this vulnerability.
3
What are the affected versions for CVE-2025-48642?
CVE-2025-48642 affects Google Android versions 14.0, 15.0, and 16.0 along with specific beta versions.
4
Is user interaction required to exploit CVE-2025-48642?
No, user interaction is not required to exploit CVE-2025-48642.
5
What type of vulnerability is CVE-2025-48642 classified as?
CVE-2025-48642 is classified as an information disclosure vulnerability.