cbcvebase.
CVE-2025-48626
published 2025-12-08

CVE-2025-48626: In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote…

PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.34%
26.6th percentile
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

19 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformframeworks_base>= 13:0 < 13:2025-12-0113:2025-12-01
platformframeworks_base>= 14:0 < 14:2025-12-0114:2025-12-01
platformframeworks_base>= 15:0 < 15:2025-12-0115:2025-12-01
platformframeworks_base>= 16-qpr2-next:0 < 16-qpr2-next:2025-12-0116-qpr2-next:2025-12-01
platformframeworks_base>= 16:0 < 16:2025-12-0116:2025-12-01
platformpackages_apps_launcher3>= 13:0 < 13:2025-12-0113:2025-12-01
platformpackages_apps_launcher3>= 14:0 < 14:2025-12-0114:2025-12-01
platformpackages_apps_launcher3>= 15:0 < 15:2025-12-0115:2025-12-01
platformpackages_apps_launcher3>= 16-qpr2-next:0 < 16-qpr2-next:2025-12-0116-qpr2-next:2025-12-01
platformpackages_apps_launcher3>= 16:0 < 16:2025-12-0116:2025-12-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability allows launching an application from the background due to a precondition check failure, enabling remote escalation of privilege without user interaction — monitor for unexpected background app launches or activity starts from non-foreground processes on Android 13–16.
  • Affects Android (AOSP) versions 13, 14, 15, and 16 — prioritize detection and patching on devices running these versions; track Android Security Bulletin 2025-12-01 patch level for remediation status.
  • ·The vulnerability is classified as EoP (Elevation of Privilege) with HIGH severity and is exploitable remotely with no additional privileges or user interaction required, making it a high-priority patch target.
  • ·The issue is tracked internally by Google as A-381339822; no public proof-of-concept or specific file/component details are disclosed in available sources, limiting precise detection rule authoring.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.