cbcvebase.
CVE-2025-48646
published 2026-03-02

CVE-2025-48646: In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Affected

13 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0
platformframeworks_base>= 14:0 < 14:2026-03-0114:2026-03-01
platformframeworks_base>= 15:0 < 15:2026-03-0115:2026-03-01
platformframeworks_base>= 16-qpr2-next:0 < 16-qpr2-next:2026-03-0116-qpr2-next:2026-03-01
platformframeworks_base>= 16-qpr2:0 < 16-qpr2:2026-03-0116-qpr2:2026-03-01
platformframeworks_base>= 16:0 < 16:2026-03-0116:2026-03-01