CVE-2025-48561Observable Discrepancy in Google Android

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 4
Latest updateOct 14

Description

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

2
CVEList
CVE-2025-48561: In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure2025-09-04
GHSA
GHSA-r9mm-fg76-g89p: In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure2025-09-04

🕵️Threat Intelligence

1
Bleepingcomputer
New Android Pixnapping attack steals MFA codes pixel-by-pixel2025-10-14
CVE-2025-48561 — Observable Discrepancy in Google | cvebase