Local Privilege Escalation Vulnerability in Android Framework by Google
CVE-2025-48522

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48522?

A logic error in the setDisplayName method of AssociationRequest.java allows for potential retention of the Content Decryption Module (CDM) association. This flaw could enable local privilege escalation without requiring any additional execution privileges, making it exploitable without user interaction. As a result, attackers may be able to gain unauthorized access to sensitive operations within the Android environment, thereby compromising the security and integrity of the system.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.