cbcvebase.
CVE-2025-48543
published 2025-09-04

CVE-2025-48543: In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local…

PriorityP183high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-09-25
Exploited in the wild
EPSS
0.55%
42.2th percentile
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

14 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformart>= 13:0 < 13:2025-09-0113:2025-09-01
platformart>= 14:0 < 14:2025-09-0114:2025-09-01
platformart>= 15:0 < 15:2025-09-0115:2025-09-01
platformart>= 16-next:0 < 16-next:2025-09-0116-next:2025-09-01
platformart>= 16:0 < 16:2025-09-0116:2025-09-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability class is Use-After-Free in Android Runtime enabling Chrome sandbox escape to attack system_server; monitor for unexpected privilege escalation from Chrome/browser processes to system_server on Android devices
  • No user interaction is required for exploitation; treat any anomalous system_server crashes or privilege changes originating from browser sandbox processes as high-priority indicators
  • Affected Android versions are 13, 14, 15, and 16; scope detection and patching efforts to devices running these AOSP versions
  • Track Android Security Bulletin reference A-421834866 for patch availability and apply vendor mitigations by the CISA-mandated remediation due date of 2025-09-25
  • CISA has added this to the Known Exploited Vulnerabilities catalog, indicating active in-the-wild exploitation; prioritize detection of local EoP attempts via Android Runtime on managed/enterprise Android fleets
  • ·Exploitation requires no additional execution privileges and no user interaction, meaning the attack surface is broad across all affected Android versions (13–16); standard privilege-gating controls are insufficient as a sole mitigation
  • ·The vulnerability is located 'in multiple locations' within Android Runtime, suggesting the attack surface is not limited to a single code path and detection rules should not be narrowly scoped

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.