CVE-2025-48633
published 2025-12-08CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code…
PriorityP181medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-12-23
Exploited in the wild
EPSS
0.25%
16.3th percentile
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| platform | frameworks_base | >= 13:0 < 13:2025-12-01 | 13:2025-12-01 |
| platform | frameworks_base | >= 14:0 < 14:2025-12-01 | 14:2025-12-01 |
| platform | frameworks_base | >= 15:0 < 15:2025-12-01 | 15:2025-12-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2025-12-01 | 16-qpr2-next:2025-12-01 |
| platform | frameworks_base | >= 16:0 < 16:2025-12-01 | 16:2025-12-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in hasAccountsOnAnyUser() method of DevicePolicyManagerService.java — monitor for unexpected Device Owner provisioning events on already-provisioned devices, which would indicate exploitation of this logic error. ↗
- →CVE-2025-48633 was tagged as under limited, targeted exploitation in the wild as of December 2025 — prioritize detection on high-value/high-profile Android targets consistent with commercial spyware or nation-state TTPs. ↗
- →No additional execution privileges or user interaction are required for exploitation — the attack can be performed entirely locally by an unprivileged app, so monitor for unexpected Device Owner additions from non-system processes. ↗
- →Affected AOSP versions are 13, 14, 15, and 16 — scope detection and patch verification efforts to devices running these versions that have not applied the 2025-12-01 security patch level. ↗
- ·Google has not shared technical details about the flaw or the ongoing attacks — no public PoC or exploit chain details are available, limiting the ability to write precise behavioral signatures. ↗
- ·The CISA KEV entry describes the vulnerability as 'information disclosure' while NVD/Android bulletin classifies it as a local privilege escalation (Device Owner addition) — ensure detection logic covers both the ID type and EoP impact as classified under A-417988098. ↗
- ·Pixel devices receive patches immediately but other OEM devices lag — patch-level verification cannot be used as a sole indicator of protection across the Android ecosystem. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vulncheck5.5MEDIUM
cisa5.5MEDIUM
vendor_msrc2.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Android Framework Information Disclosure Vulnerability
cisa·2025-12-02·CVSS 5.5
CVE-2025-48633 [MEDIUM] Android Framework Information Disclosure Vulnerability
Vulnerability: Android Framework Information Disclosure Vulnerability
Affected: Android Framework
Android Framework contains an unspecified vulnerability that allows for information disclosure.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://source.android.com/docs/security/bulletin/2025-12-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48633
Remediation Due Date: 2025-12-23
Android
CVE-2025-48633: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48633
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14, 15, 16
References: A-417988098
vendor_android·2025-12-01·CVSS 5.5
CVE-2025-48633 [MEDIUM] CVE-2025-48633: Android Security Bulletin 2025-12-01
CVE: CVE-2025-48633
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14, 15, 16
References: A-417988098
Android Security Bulletin 2025-12-01
CVE: CVE-2025-48633
Severity: HIGH
Type: ID
Affected AOSP versions: 13, 14, 15, 16
References: A-417988098
Microsoft
drm/gma500: Fix WARN_ON(lock->magic != lock) error
vendor_msrc·2024-04-09·CVSS 2.3
CVE-2022-48633 [MEDIUM] CWE-617 drm/gma500: Fix WARN_ON(lock->magic != lock) error
drm/gma500: Fix WARN_ON(lock->magic != lock) error
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
GHSA
GHSA-2jv4-596w-g9hj: In hasAccountsOnAnyUser of DevicePolicyManagerService
ghsa_unreviewed·2025-12-08
CVE-2025-48633 [HIGH] GHSA-2jv4-596w-g9hj: In hasAccountsOnAnyUser of DevicePolicyManagerService
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService
osv·2025-12-01
CVE-2025-48633 CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
VulnCheck
Android Framework Information Disclosure Vulnerability
vulncheck·2025·CVSS 5.5
CVE-2025-48633 [MEDIUM] Android Framework Information Disclosure Vulnerability
Android Framework Information Disclosure Vulnerability
Android Framework contains an unspecified vulnerability that allows for information disclosure.
Affected: Android Framework
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://source.android.com/docs/security/bulletin/2025-12-01; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.recordedfuture.com/blog/december-2025-cve-landscape; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025
Remediation Due: 2025-12-23
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Google fixes one actively exploited Android zero-day, 124 flaws
blogs_bleepingcomputer·2026-06-02·CVSS 7.8
CVE-2025-48595 [HIGH] Google fixes one actively exploited Android zero-day, 124 flaws
## Google fixes one actively exploited Android zero-day, 124 flaws
## Sergiu Gatlan
"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible."
While Google has yet to share technical details about the flaw or provide more information about the ongoing attacks targeting it, similar flaws have been exploited in the past by commercial spyware and by nation-state operations targeting high-profile or high-interest individuals.
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and e
Bleepingcomputer
Android gets patches for Qualcomm zero-day exploited in attacks
blogs_bleepingcomputer·2026-03-03·CVSS 7.8
CVE-2026-21385 [HIGH] Android gets patches for Qualcomm zero-day exploited in attacks
## Android gets patches for Qualcomm zero-day exploited in attacks
## Sergiu Gatlan
Qualcomm says it was alerted to this high-severity vulnerability on December 18 by Google's Android Security team , and it notified customers on February 2. According to its February advisory, which has yet to flag CVE-2026-21385 as exploited in attacks, the security flaw affects 235 Qualcomm chipsets.
"We commend the researchers from Google’s Threat Analysis Group for using coordinated disclosure practices," a Qualcomm spokesperson told BleepingComputer. "Regarding their GPU-related research, fixes were made available to our customers in January 2026. We encourage end users to apply security updates as they become available from device makers."
With this month's Android security updates, Google fixed 1
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·CVSS 7.8
CVE-2025-55182 [HIGH] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
# December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
- React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
- China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
- Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-conce
2025-12-08
Published
2025-12-02
Added to CISA KEV
Exploited in the wild