Logic Error in Contacts Application Leads to Unintended Contact Addition by Android
CVE-2025-48523
7.8HIGH
What is CVE-2025-48523?
A potential security vulnerability exists in the Android Contacts application where a logic flaw in the onCreate method of SelectAccountActivity.java allows the addition of contacts without the necessary permissions. This issue enables local privilege escalation without requiring user interaction, posing a significant risk to user privacy and data security. Addressing this vulnerability is crucial for maintaining the integrity of contact management on Android devices.
Affected Version(s)
Android 16
Android 15
Android 14