CVE-2025-48572
9.5 CISA KEVGoogle · Android Framework
A permissions bypass in the Android Framework allows local privilege escalation by launching activities from the background without user interaction.
Executive summary
This critical privilege escalation vulnerability in the Android Framework is currently being exploited in the wild and requires immediate remediation.
Vulnerability
The flaw stems from a permissions bypass that enables an attacker to launch activities from the background. This vulnerability allows for local escalation of privilege without requiring additional execution permissions or user interaction.
Business impact
The ability to escalate privileges locally on an Android device poses a severe threat to data confidentiality and system integrity. An attacker who successfully exploits this vulnerability can gain elevated access to the device, potentially bypassing security controls to access sensitive user data or install malicious applications. Given the high CVSS score of 9.5 and confirmed active exploitation, this flaw represents a critical business risk that could lead to full device compromise.
Remediation
Immediate Action: Deploy the official security update provided by Google in the December 2025 Android Security Bulletin to all affected devices.
Proactive Monitoring: Monitor device logs for unusual activity or unauthorized application launches occurring from background processes.
Compensating Controls: Ensure that Google Play Protect is enabled and updated to its latest version to assist in detecting and blocking potential exploitation attempts.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The presence of confirmed active exploitation in the CISA Known Exploited Vulnerabilities catalog mandates an urgent response. Organizations must prioritize the deployment of the December 2025 security patches across all managed Android assets. Delaying these updates leaves devices exposed to a critical elevation of privilege attack that requires no user interaction to execute.
More Google CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written