cbcvebase.
CVE-2025-48548
published 2025-09-04

CVE-2025-48548: In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition…

high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

Affected

15 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformframeworks_av>= 13:0 < 13:2025-09-0113:2025-09-01
platformframeworks_av>= 14:0 < 14:2025-09-0114:2025-09-01
platformframeworks_av>= 15:0 < 15:2025-09-0115:2025-09-01
platformframeworks_av>= 16-next:0 < 16-next:2025-09-0116-next:2025-09-01
platformframeworks_base>= 13:0 < 13:2025-09-0113:2025-09-01
platformframeworks_base>= 14:0 < 14:2025-09-0114:2025-09-01
platformframeworks_base>= 15:0 < 15:2025-09-0115:2025-09-01
platformframeworks_base>= 16-next:0 < 16-next:2025-09-0116-next:2025-09-01