CVE-2025-48602
8.4Google · Android
A logic error in KeyguardViewMediator.java allows for a local lockscreen bypass and subsequent escalation of privilege on affected Android devices.
Executive summary
A critical logic error in the Android KeyguardViewMediator component enables an unauthenticated local attacker to bypass the lockscreen and escalate privileges without requiring user interaction.
Vulnerability
The vulnerability is an elevation of privilege flaw stemming from a logic error within the exitKeyguardAndFinishSurfaceBehindRemoteAnimation function of KeyguardViewMediator.java. This allows an unauthenticated local attacker to bypass device security mechanisms.
Business impact
The ability to bypass the lockscreen on mobile devices poses a severe threat to data confidentiality and integrity, as it grants unauthorized access to sensitive information stored on the device. Given the CVSS score of 8.4, this vulnerability is classified as High severity and requires immediate attention to prevent unauthorized access to enterprise data.
Remediation
Immediate Action: Apply the security updates provided in the March 2026 Android Security Bulletin immediately to all managed devices.
Proactive Monitoring: Monitor device security logs for signs of unauthorized access or unexpected privilege escalation events.
Compensating Controls: Enforce full device encryption and utilize mobile device management (MDM) policies to restrict physical access and disable untrusted USB debugging interfaces where possible.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability represents a significant risk to the security posture of mobile endpoints running affected versions of Android. Organizations should prioritize the deployment of the March 2026 security patches to all affected handsets to eliminate the risk of lockscreen bypass and unauthorized privilege escalation.