CVE-2025-48543

9.5 CISA KEV

Google · Android Runtime

A use-after-free vulnerability in the Android Runtime allows an attacker to escape the Chrome sandbox, leading to local privilege escalation against the system_server.

Executive summary

This critical use-after-free vulnerability in the Android Runtime is currently being actively exploited in the wild and poses a severe risk of unauthorized system-level privilege escalation.

Vulnerability

This is a use-after-free vulnerability that enables an attacker to escape the Chrome sandbox and compromise the system_server component. The exploit requires only local access and does not require user interaction to achieve elevation of privilege.

Business impact

The exploitation of this vulnerability allows an attacker to bypass critical security boundaries, granting them elevated privileges that could lead to full system compromise. Given the CVSS score of 9.5 and confirmed active exploitation, organizations face a high risk of data theft, unauthorized configuration changes, and total loss of system integrity.

Remediation

Immediate Action: Apply the September 2025 Android Security Bulletin updates provided by Google to all affected devices immediately.

Proactive Monitoring: Review system logs for unusual process behavior or unauthorized attempts to access the system_server or interact with the Android Runtime environment.

Compensating Controls: While software updates are the only definitive fix, ensure that mobile device management policies restrict the installation of untrusted applications, which may serve as an entry point for local exploitation.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

The severity and confirmed active exploitation of this vulnerability necessitate an immediate response. Security teams should prioritize the deployment of the September 2025 security patches across all managed Android devices to prevent potential system compromise. If patching is delayed, isolate affected devices from sensitive environments to mitigate the impact of a successful privilege escalation attack.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section, carried in 20 daily briefs, Sep 4 to Sep 24
  3. Analyst report written

Sources