CVE-2025-48651
published 2026-04-06CVE-2025-48651: In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.10%
0.8th percentile
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android privilege escalation
vuldb·2026-07-21·CVSS 5.5
CVE-2025-48651 [MEDIUM] Google Android privilege escalation
A vulnerability labeled as problematic has been found in Google Android. This affects an unknown function. The manipulation results in privilege escalation.
This vulnerability was named CVE-2025-48651. The attack needs to be approached within the local network. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-9wq4-qr6w-vc44: StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467
ghsa_unreviewed·2026-04-06
CVE-2025-48651 GHSA-9wq4-qr6w-vc44: StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467
StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467762899.
No detection rules found.
No public exploits indexed.
2026-04-06
Published