CVE-2025-48653: High severity Google Android vulnerability
In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48653?
CVE-2025-48653 has been rated as moderate severity due to the potential for local escalation of privilege.
How do I fix CVE-2025-48653?
To mitigate CVE-2025-48653, users should update their Android devices to the latest available version that addresses this vulnerability.
What versions of Android are affected by CVE-2025-48653?
CVE-2025-48653 affects Android versions 14.0, 15.0, and 16.0, including specific beta releases of 16.0.
Can CVE-2025-48653 be exploited without user interaction?
Yes, CVE-2025-48653 can be exploited without any user interaction, making it particularly concerning.
What impact does CVE-2025-48653 have on system security?
CVE-2025-48653 can allow an attacker to escalate privileges locally without requiring additional execution privileges.