CVE-2025-48572
published 2025-12-08CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of…
PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
0.25%
16.0th percentile
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2025-12-01 | 13:2025-12-01 |
| platform | frameworks_base | >= 14:0 < 14:2025-12-01 | 14:2025-12-01 |
| platform | frameworks_base | >= 15:0 < 15:2025-12-01 | 15:2025-12-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2025-12-01 | 16-qpr2-next:2025-12-01 |
| platform | frameworks_base | >= 16:0 < 16:2025-12-01 | 16:2025-12-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-48572 is an Android Framework privilege escalation vulnerability allowing background activity launches; flag devices running Android 13, 14, 15, or 16 that have not applied the 2025-12-01 security patch level or later. ↗
- →CVE-2025-48572 has been confirmed under active, limited, targeted exploitation — treat unpatched Android Framework devices as high-priority targets consistent with commercial spyware or nation-state tradecraft. ↗
- →The vulnerability enables background activity launches via a permissions bypass leading to local privilege escalation — monitor for unexpected foreground activity starts originating from background processes on Android devices. ↗
- →CISA added CVE-2025-48572 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2025-12-23; use this as a compliance/detection threshold for unpatched asset identification. ↗
- ·Google Pixel devices receive the patch immediately, but other Android OEM vendors typically take longer to test and deploy patches for their specific hardware configurations — patched status cannot be assumed based on Android version alone. ↗
- ·The 2025-12-05 security patch level bundles all fixes from the 2025-12-01 batch plus patches for closed-source third-party and kernel subcomponents; the latter may not apply to all Android devices, so patch-level checks must account for device-specific applicability. ↗
- ·No additional execution privileges are required and user interaction is not needed for exploitation, meaning the attack surface is broad and exploitation can be fully silent. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Android Framework Privilege Escalation Vulnerability
cisa·2025-12-02·CVSS 7.8
CVE-2025-48572 [HIGH] Android Framework Privilege Escalation Vulnerability
Vulnerability: Android Framework Privilege Escalation Vulnerability
Affected: Android Framework
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://source.android.com/docs/security/bulletin/2025-12-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48572
Remediation Due Date: 2025-12-23
Android
CVE-2025-48572: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48572
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15, 16
References: A-385736540
vendor_android·2025-12-01·CVSS 7.8
CVE-2025-48572 [HIGH] CVE-2025-48572: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48572
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15, 16
References: A-385736540
Android Security Bulletin 2025-12-01
CVE: CVE-2025-48572
Severity: HIGH
Type: EoP
Affected AOSP versions: 13, 14, 15, 16
References: A-385736540
GHSA
GHSA-4rw8-q5j6-vc96: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
ghsa_unreviewed·2025-12-08
CVE-2025-48572 [HIGH] CWE-306 GHSA-4rw8-q5j6-vc96: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
osv·2025-12-01
CVE-2025-48572 CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
VulnCheck
Android Framework Privilege Escalation Vulnerability
vulncheck·2025·CVSS 7.8
CVE-2025-48572 [HIGH] Android Framework Privilege Escalation Vulnerability
Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Affected: Android Framework
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://source.android.com/docs/security/bulletin/2025-12-01; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.recordedfuture.com/blog/december-2025-cve-landscape; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Remediation Due: 2025-12-23
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Google fixes one actively exploited Android zero-day, 124 flaws
blogs_bleepingcomputer·2026-06-02·CVSS 7.8
CVE-2025-48595 [HIGH] Google fixes one actively exploited Android zero-day, 124 flaws
## Google fixes one actively exploited Android zero-day, 124 flaws
## Sergiu Gatlan
"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible."
While Google has yet to share technical details about the flaw or provide more information about the ongoing attacks targeting it, similar flaws have been exploited in the past by commercial spyware and by nation-state operations targeting high-profile or high-interest individuals.
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and e
Bleepingcomputer
Android gets patches for Qualcomm zero-day exploited in attacks
blogs_bleepingcomputer·2026-03-03·CVSS 7.8
CVE-2026-21385 [HIGH] Android gets patches for Qualcomm zero-day exploited in attacks
## Android gets patches for Qualcomm zero-day exploited in attacks
## Sergiu Gatlan
Qualcomm says it was alerted to this high-severity vulnerability on December 18 by Google's Android Security team , and it notified customers on February 2. According to its February advisory, which has yet to flag CVE-2026-21385 as exploited in attacks, the security flaw affects 235 Qualcomm chipsets.
"We commend the researchers from Google’s Threat Analysis Group for using coordinated disclosure practices," a Qualcomm spokesperson told BleepingComputer. "Regarding their GPU-related research, fixes were made available to our customers in January 2026. We encourage end users to apply security updates as they become available from device makers."
With this month's Android security updates, Google fixed 1
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·CVSS 7.8
CVE-2025-55182 [HIGH] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
# December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
- React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
- China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
- Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-conce
2025-12-08
Published
2025-12-02
Added to CISA KEV
Exploited in the wild