CVE-2025-48630

7.4

Google · Android

A side channel information disclosure vulnerability in the SkiaRenderEngine component of Android allows for local escalation of privilege without user interaction.

Executive summary

A high-severity local privilege escalation vulnerability in Android's SkiaRenderEngine could allow an attacker to gain unauthorized access to the GPU cache.

Vulnerability

This flaw exists in the drawLayersInternal function of SkiaRenderEngine.cpp, where a side channel allows unauthorized access to the GPU cache, enabling local escalation of privilege for an unauthenticated attacker.

Business impact

The vulnerability carries a CVSS score of 7.4, indicating a high risk of local exploitation. Successful execution could allow a malicious actor to bypass security boundaries, potentially leading to total system compromise, data theft, and unauthorized administrative control over the affected mobile device.

Remediation

Immediate Action: Apply the March 2026 Android security updates provided by Google or your device manufacturer as soon as they become available.

Proactive Monitoring: Security teams should monitor system logs for unusual process activity or attempts to access restricted graphics memory regions.

Compensating Controls: Ensure that device-level security policies and restricted application environments are strictly enforced to limit the impact of local privilege escalation attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant risk to device integrity, as it enables privilege escalation without requiring user interaction. Organizations must prioritize the deployment of the March 2026 security patches across their mobile fleet to mitigate the risk of local exploitation.

More Google CVEs

Sources