cbcvebase.
CVE-2025-48572
published 2025-12-08

CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of…

PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
0.23%
14.1th percentile
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

14 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformframeworks_base>= 13:0 < 13:2025-12-0113:2025-12-01
platformframeworks_base>= 14:0 < 14:2025-12-0114:2025-12-01
platformframeworks_base>= 15:0 < 15:2025-12-0115:2025-12-01
platformframeworks_base>= 16-qpr2-next:0 < 16-qpr2-next:2025-12-0116-qpr2-next:2025-12-01
platformframeworks_base>= 16:0 < 16:2025-12-0116:2025-12-01

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-48572 is an Android Framework privilege escalation vulnerability allowing background activity launches; flag devices running Android 13, 14, 15, or 16 that have not applied the 2025-12-01 security patch level or later.
  • CVE-2025-48572 has been confirmed under active, limited, targeted exploitation — treat unpatched Android Framework devices as high-priority targets consistent with commercial spyware or nation-state tradecraft.
  • The vulnerability enables background activity launches via a permissions bypass leading to local privilege escalation — monitor for unexpected foreground activity starts originating from background processes on Android devices.
  • CISA added CVE-2025-48572 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2025-12-23; use this as a compliance/detection threshold for unpatched asset identification.
  • ·Google Pixel devices receive the patch immediately, but other Android OEM vendors typically take longer to test and deploy patches for their specific hardware configurations — patched status cannot be assumed based on Android version alone.
  • ·The 2025-12-05 security patch level bundles all fixes from the 2025-12-01 batch plus patches for closed-source third-party and kernel subcomponents; the latter may not apply to all Android devices, so patch-level checks must account for device-specific applicability.
  • ·No additional execution privileges are required and user interaction is not needed for exploitation, meaning the attack surface is broad and exploitation can be fully silent.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.