CVE-2025-48597
7.8Google · Android
A tapjacking or overlay vulnerability in Android allows for local privilege escalation by tricking users into granting permissions without interaction.
Executive summary
A critical vulnerability in Google Android versions 14, 15, and 16 could allow an attacker to achieve local privilege escalation via a tapjacking attack.
Vulnerability
This is an elevation of privilege vulnerability occurring in multiple locations of the Android framework, where an attacker can utilize tapjacking or overlay techniques to bypass permission prompts. The attack requires low privileges on the local system but does not require any additional user interaction to execute.
Business impact
The ability for a local attacker to escalate privileges poses a significant risk to the integrity and confidentiality of the mobile device. Successful exploitation could grant an attacker unauthorized access to sensitive user data, system functions, or installed applications, effectively bypassing the security model of the Android operating system. Given the CVSS score of 7.8, this flaw represents a high-severity risk that could lead to complete system compromise if left unaddressed.
Remediation
Immediate Action: Update all affected Google Android devices to the latest security patch level provided by the manufacturer or the Android Security Bulletin for December 2025.
Proactive Monitoring: Monitor device security logs for unusual permission-related events or suspicious application behavior that may indicate an attempt to overlay system UI elements.
Compensating Controls: Ensure that only applications from trusted sources are installed on devices, and strictly limit the use of accessibility services or overlay permissions for third-party applications.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a high risk to Android users by undermining the core permission structure of the operating system. Security teams and individual users should prioritize the deployment of the December 2025 security updates to mitigate the risk of local privilege escalation. Immediate patching is the most effective method to neutralize this attack vector.