CVE-2025-48575

7.8

Google · Android

A permissions bypass in CertInstaller.java allows local attackers to install arbitrary certificates, resulting in local elevation of privilege without user interaction.

Executive summary

A critical local privilege escalation vulnerability in Google Android's CertInstaller component permits unauthorized certificate installation and full system compromise.

Vulnerability

This vulnerability resides in multiple functions within CertInstaller.java, where a permissions bypass enables a local attacker with low privileges to escalate their access level without requiring user interaction.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity risk due to the potential for total system compromise. Successful exploitation allows an attacker to gain elevated privileges on the device, potentially leading to unauthorized access to sensitive data, installation of malicious applications, or persistent control over the user environment.

Remediation

Immediate Action: Update affected Android devices to the latest security patch level provided by the vendor as detailed in the December 2025 Android Security Bulletin.

Proactive Monitoring: Monitor system logs for unexpected certificate installation events or unauthorized attempts to access protected system settings by low-privileged applications.

Compensating Controls: Ensure that device management policies restrict the installation of untrusted or unknown root certificates via Mobile Device Management (MDM) solutions.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the Android security model. Organizations and individual users should prioritize applying the December 2025 security updates immediately to mitigate the risk of local privilege escalation. Ensuring that all devices are running the latest firmware is the only effective way to remediate this flaw.

More Google CVEs

Sources