CVE-2025-48634
published 2026-03-02CVE-2025-48634: In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escalation of…
PriorityP339high7.3CVSS 3.1
AVLACLPRNUINSUCLIHAL
EPSS
0.09%
0.8th percentile
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | frameworks_base | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | frameworks_base | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9h56-23gj-953r: In relayoutWindow of WindowManagerService
ghsa_unreviewed·2026-03-02
CVE-2025-48634 [HIGH] CWE-862 GHSA-9h56-23gj-953r: In relayoutWindow of WindowManagerService
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-48634: In relayoutWindow of WindowManagerService
osv·2026-03-01
CVE-2025-48634 CVE-2025-48634: In relayoutWindow of WindowManagerService
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Suricata
ET WEB_SPECIFIC_APPS D-Link SetWLanRadioSecurity Key Parameter Command Injection Attempt (CVE-2024-48634)
suricata·2025-10-10·CVSS 8.0
CVE-2024-48634 [HIGH] ET WEB_SPECIFIC_APPS D-Link SetWLanRadioSecurity Key Parameter Command Injection Attempt (CVE-2024-48634)
ET WEB_SPECIFIC_APPS D-Link SetWLanRadioSecurity Key Parameter Command Injection Attempt (CVE-2024-48634)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link SetWLanRadioSecurity Key Parameter Command Injection Attempt (CVE-2024-48634)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:6; content:"/HNAP1"; http.request_body; content:"|3c 3f|xml|20|version|3d 22|1.0|22|"; content:"|3c|SetWLanRadioSecurity"; fast_pattern; content:"|3c|Key|3e|"; pcre:"/^[^\x3e]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2024-48634; classtype:attempted-admin; sid:2065142; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_10, cve CVE_2024_4863
No public exploits indexed.
2026-03-02
Published