CVE-2025-48650

8.4

Google · Android

A SQL injection vulnerability in multiple Android components allows local unauthenticated attackers to achieve elevation of privilege.

Executive summary

A critical SQL injection vulnerability in Google Android versions 14, 15, and 16 allows local attackers to elevate privileges without user interaction.

Vulnerability

This vulnerability involves a SQL injection flaw present in multiple locations within the Android operating system. An unauthenticated local attacker can exploit this weakness to escalate privileges without requiring additional execution permissions or user interaction.

Business impact

The ability for a local attacker to escalate privileges to a higher level of authority poses a severe risk to device integrity and user data privacy. Given the CVSS score of 8.4, this vulnerability is classified as High severity, as it bypasses standard OS security boundaries and could lead to complete system compromise or unauthorized access to sensitive application data.

Remediation

Immediate Action: Organizations and users should monitor the official Google Android security bulletin for the release of security patches and apply them to all affected devices as soon as they become available.

Proactive Monitoring: Security teams should monitor device logs for suspicious system calls or unexpected database queries that might indicate an attempt to interact with vulnerable internal components.

Compensating Controls: Ensure that all applications adhere to the principle of least privilege and maintain strict enforcement of Android permission models to limit the potential reach of an elevated local attacker.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This SQL injection flaw represents a significant elevation of privilege risk for Android users. Because the vulnerability requires no user interaction and provides high impact, it is imperative to prioritize the deployment of vendor-provided security updates once they are published in the Android security bulletin.

More Google CVEs

Sources