CVE-2025-48594
published 2025-12-08CVE-2025-48594: In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper…
PriorityP341high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.08%
0.2th percentile
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14:0 < 14:2025-12-01 | 14:2025-12-01 |
| platform | frameworks_base | >= 15:0 < 15:2025-12-01 | 15:2025-12-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2025-12-01 | 16-qpr2-next:2025-12-01 |
| platform | frameworks_base | >= 16:0 < 16:2025-12-01 | 16:2025-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2025-48594: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48594
Severity: HIGH
Type: EoP
Affected AOSP versions: 14, 15, 16
References: A-427206637
vendor_android·2025-12-01·CVSS 7.3
CVE-2025-48594 [HIGH] CVE-2025-48594: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48594
Severity: HIGH
Type: EoP
Affected AOSP versions: 14, 15, 16
References: A-427206637
Android Security Bulletin 2025-12-01
CVE: CVE-2025-48594
Severity: HIGH
Type: EoP
Affected AOSP versions: 14, 15, 16
References: A-427206637
GHSA
GHSA-6mpj-6cjq-hh75: In onUidImportance of DisassociationProcessor
ghsa_unreviewed·2025-12-08
CVE-2025-48594 [HIGH] CWE-20 GHSA-6mpj-6cjq-hh75: In onUidImportance of DisassociationProcessor
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
OSV
CVE-2025-48594: In onUidImportance of DisassociationProcessor
osv·2025-12-01
CVE-2025-48594 CVE-2025-48594: In onUidImportance of DisassociationProcessor
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-08
Published