CVE-2025-48555

7.8

Google · Android

A cross-profile information disclosure vulnerability in NotificationStation.java allows for local privilege escalation without user interaction.

Executive summary

A critical local privilege escalation vulnerability exists in Google Android, potentially allowing attackers to gain unauthorized system access.

Vulnerability

This flaw involves a confused deputy issue within NotificationStation.java, enabling information disclosure and local escalation of privilege. The vulnerability is exploitable by an attacker with low privileges and does not require user interaction.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of risk for Android device integrity. A successful exploit could allow a malicious application or local actor to bypass security boundaries, potentially leading to unauthorized data access, system manipulation, or complete control over the affected device.

Remediation

Immediate Action: Organizations and users must apply the latest security patches provided by Google through the December 2025 Android Security Bulletin. Ensure all devices are running the most recent system update to mitigate this local privilege escalation risk.

Proactive Monitoring: Security teams should monitor device logs for unexpected system-level processes or unauthorized attempts to access cross-profile notification data.

Compensating Controls: Enforce strict application sandboxing policies and restrict the installation of applications from untrusted sources to limit the potential for malicious code to execute locally on the device.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for local privilege escalation and the authoritative confirmation from the Google Android security bulletin, this vulnerability must be treated with high priority. Administrators should expedite the deployment of the December 2025 security updates to all managed Android devices to prevent potential exploitation.

More Google CVEs

Sources