CVE-2025-48592
published 2025-12-08CVE-2025-48592: In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
23.7th percentile
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 15:0 < 15:2025-12-01 | 15:2025-12-01 |
| platform | frameworks_av | >= 16-qpr2-next:0 < 16-qpr2-next:2025-12-01 | 16-qpr2-next:2025-12-01 |
| platform | frameworks_av | >= 16:0 < 16:2025-12-01 | 16:2025-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2025-48592: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48592
Severity: HIGH
Type: ID
Affected AOSP versions: 15, 16
References: A-427113482
vendor_android·2025-12-01·CVSS 7.5
CVE-2025-48592 [HIGH] CVE-2025-48592: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48592
Severity: HIGH
Type: ID
Affected AOSP versions: 15, 16
References: A-427113482
Android Security Bulletin 2025-12-01
CVE: CVE-2025-48592
Severity: HIGH
Type: ID
Affected AOSP versions: 15, 16
References: A-427113482
GHSA
GHSA-2754-h3wv-g4xx: In initDecoder of C2SoftDav1dDec
ghsa_unreviewed·2025-12-08
CVE-2025-48592 [HIGH] CWE-122 GHSA-2754-h3wv-g4xx: In initDecoder of C2SoftDav1dDec
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-48592: In initDecoder of C2SoftDav1dDec
osv·2025-12-01
CVE-2025-48592 CVE-2025-48592: In initDecoder of C2SoftDav1dDec
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-08
Published