CVE-2025-48648
published 2026-06-01CVE-2025-48648: In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.07%
0.0th percentile
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 14/15/16 NotificationManagerService.java denial of service (WID-SEC-2026-1772)
vuldb·2026-06-03·CVSS 5.5
CVE-2025-48648 [MEDIUM] Google Android 14/15/16 NotificationManagerService.java denial of service (WID-SEC-2026-1772)
A vulnerability identified as critical has been detected in Google Android 14/15/16. This affects an unknown part of the file NotificationManagerService.java. This manipulation causes denial of service.
This vulnerability is handled as CVE-2025-48648. It is possible to launch the attack on the local host. There is not any exploit available.
GHSA
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion.
ghsa_unreviewed·2026-06-02
CVE-2025-48648 [MEDIUM] CWE-400 In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion.
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-01
Published