Logic Error in Contacts Application Leads to Unintended Contact Addition by Android
CVE-2025-48523

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48523?

A potential security vulnerability exists in the Android Contacts application where a logic flaw in the onCreate method of SelectAccountActivity.java allows the addition of contacts without the necessary permissions. This issue enables local privilege escalation without requiring user interaction, posing a significant risk to user privacy and data security. Addressing this vulnerability is crucial for maintaining the integrity of contact management on Android devices.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.