CVE-2025-48645: Input Validation
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48645?
CVE-2025-48645 has a moderate severity rating due to its potential for local escalation of privileges.
How do I fix CVE-2025-48645?
To mitigate CVE-2025-48645, ensure that your Android device is updated to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2025-48645?
CVE-2025-48645 affects Android versions 14.0, 15.0, and 16.0 through various beta releases.
What is the impact of exploiting CVE-2025-48645?
Exploiting CVE-2025-48645 can lead to a persistent package issue, allowing local escalation of privileges without user interaction.
Is user interaction required to exploit CVE-2025-48645?
No, exploitation of CVE-2025-48645 does not require user interaction, making it a more serious threat.