CVE-2025-48612
7.8Google · Android
A local privilege escalation vulnerability in Android allows an application to improperly modify the default NFC payment setting for the main user profile.
Executive summary
A local privilege escalation vulnerability in Google Android versions 14, 15, 16, and 16-qpr2 poses a significant security risk by allowing unauthorized modification of NFC payment settings.
Vulnerability
This vulnerability occurs in the setDefaultKey function of DefaultPaymentSettings.java due to improper input validation, allowing an application to overwrite critical system settings. The vulnerability can be triggered by a local attacker with low privileges, requiring no additional execution privileges or user interaction.
Business impact
Successful exploitation allows an attacker to gain elevated control over NFC payment configurations, which can lead to unauthorized financial transactions or the redirection of payment data. Given the CVSS score of 7.8, this flaw represents a high-severity risk to user integrity and financial security, potentially resulting in significant reputational and operational damage for organizations utilizing affected mobile devices.
Remediation
Immediate Action: Update all affected Android devices to the security patch level specified in the June 2026 Android Security Bulletin.
Proactive Monitoring: Monitor device audit logs for unauthorized changes to system settings or abnormal application behavior related to payment services.
Compensating Controls: Enforce strict mobile device management (MDM) policies to restrict the installation of untrusted applications and ensure that only authorized software is permitted on corporate-managed devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk to the integrity of payment systems on Android devices. Organizations should prioritize the deployment of the June 2026 security updates to all fleet devices to mitigate the risk of unauthorized privilege escalation. Failure to patch may expose users to malicious modification of core system settings.