CVE-2025-48652: High severity Google Android vulnerability
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48652?
The severity of CVE-2025-48652 is rated as high with a score of 7.8 on the CVSS scale.
What type of vulnerability is CVE-2025-48652?
CVE-2025-48652 is a vulnerability that allows local escalation of privilege due to a logic error in MDM policy checks.
How can CVE-2025-48652 be exploited?
CVE-2025-48652 can be exploited locally without user interaction, allowing an attacker to bypass MDM policies.
What software is affected by CVE-2025-48652?
CVE-2025-48652 affects Google Android software.
How do I fix CVE-2025-48652?
To fix CVE-2025-48652, ensure that your Google Android device is updated with the latest security patches provided by the manufacturer.