cbcvebase.
CVE-2025-48633
published 2025-12-08

CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code…

PriorityP181medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
0.25%
16.4th percentile
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

15 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
platformframeworks_base>= 13:0 < 13:2025-12-0113:2025-12-01
platformframeworks_base>= 14:0 < 14:2025-12-0114:2025-12-01
platformframeworks_base>= 15:0 < 15:2025-12-0115:2025-12-01
platformframeworks_base>= 16-qpr2-next:0 < 16-qpr2-next:2025-12-0116-qpr2-next:2025-12-01
platformframeworks_base>= 16:0 < 16:2025-12-0116:2025-12-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in hasAccountsOnAnyUser() method of DevicePolicyManagerService.java — monitor for unexpected Device Owner provisioning events on already-provisioned devices, which would indicate exploitation of this logic error.
  • CVE-2025-48633 was tagged as under limited, targeted exploitation in the wild as of December 2025 — prioritize detection on high-value/high-profile Android targets consistent with commercial spyware or nation-state TTPs.
  • No additional execution privileges or user interaction are required for exploitation — the attack can be performed entirely locally by an unprivileged app, so monitor for unexpected Device Owner additions from non-system processes.
  • Affected AOSP versions are 13, 14, 15, and 16 — scope detection and patch verification efforts to devices running these versions that have not applied the 2025-12-01 security patch level.
  • ·Google has not shared technical details about the flaw or the ongoing attacks — no public PoC or exploit chain details are available, limiting the ability to write precise behavioral signatures.
  • ·The CISA KEV entry describes the vulnerability as 'information disclosure' while NVD/Android bulletin classifies it as a local privilege escalation (Device Owner addition) — ensure detection logic covers both the ID type and EoP impact as classified under A-417988098.
  • ·Pixel devices receive patches immediately but other OEM devices lag — patch-level verification cannot be used as a sole indicator of protection across the Android ecosystem.

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
vendor_msrc2.3LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.