CVE-2025-48572

9.5 CISA KEV

Google · Android Framework

A permissions bypass in the Android Framework allows local privilege escalation by launching activities from the background without user interaction.

Executive summary

This critical privilege escalation vulnerability in the Android Framework is currently being exploited in the wild and requires immediate remediation.

Vulnerability

The flaw stems from a permissions bypass that enables an attacker to launch activities from the background. This vulnerability allows for local escalation of privilege without requiring additional execution permissions or user interaction.

Business impact

The ability to escalate privileges locally on an Android device poses a severe threat to data confidentiality and system integrity. An attacker who successfully exploits this vulnerability can gain elevated access to the device, potentially bypassing security controls to access sensitive user data or install malicious applications. Given the high CVSS score of 9.5 and confirmed active exploitation, this flaw represents a critical business risk that could lead to full device compromise.

Remediation

Immediate Action: Deploy the official security update provided by Google in the December 2025 Android Security Bulletin to all affected devices.

Proactive Monitoring: Monitor device logs for unusual activity or unauthorized application launches occurring from background processes.

Compensating Controls: Ensure that Google Play Protect is enabled and updated to its latest version to assist in detecting and blocking potential exploitation attempts.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The presence of confirmed active exploitation in the CISA Known Exploited Vulnerabilities catalog mandates an urgent response. Organizations must prioritize the deployment of the December 2025 security patches across all managed Android assets. Delaying these updates leaves devices exposed to a critical elevation of privilege attack that requires no user interaction to execute.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief kev section
  3. Published in the daily brief critical section
  4. Published in the daily brief critical section
  5. Published in the daily brief critical section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief high section
  9. Published in the daily brief high section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Analyst report written

Sources