CVE-2025-48543
9.5 CISA KEVGoogle · Android Runtime
A use-after-free vulnerability in the Android Runtime allows an attacker to escape the Chrome sandbox, leading to local privilege escalation against the system_server.
Executive summary
This critical use-after-free vulnerability in the Android Runtime is currently being actively exploited in the wild and poses a severe risk of unauthorized system-level privilege escalation.
Vulnerability
This is a use-after-free vulnerability that enables an attacker to escape the Chrome sandbox and compromise the system_server component. The exploit requires only local access and does not require user interaction to achieve elevation of privilege.
Business impact
The exploitation of this vulnerability allows an attacker to bypass critical security boundaries, granting them elevated privileges that could lead to full system compromise. Given the CVSS score of 9.5 and confirmed active exploitation, organizations face a high risk of data theft, unauthorized configuration changes, and total loss of system integrity.
Remediation
Immediate Action: Apply the September 2025 Android Security Bulletin updates provided by Google to all affected devices immediately.
Proactive Monitoring: Review system logs for unusual process behavior or unauthorized attempts to access the system_server or interact with the Android Runtime environment.
Compensating Controls: While software updates are the only definitive fix, ensure that mobile device management policies restrict the installation of untrusted applications, which may serve as an entry point for local exploitation.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.
Analyst recommendation
The severity and confirmed active exploitation of this vulnerability necessitate an immediate response. Security teams should prioritize the deployment of the September 2025 security patches across all managed Android devices to prevent potential system compromise. If patching is delayed, isolate affected devices from sensitive environments to mitigate the impact of a successful privilege escalation attack.
More Google CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section, carried in 20 daily briefs, Sep 4 to Sep 24
- Analyst report written