Permission Bypass Vulnerability in Android WifiPermissionsUtil by Google
CVE-2025-48524

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48524?

A vulnerability exists in the isSystem function of WifiPermissionsUtil.java that allows for a permission bypass due to a missing permission check. This could facilitate a local denial of service attack without requiring any additional execution privileges or user interaction, potentially disrupting the normal functionality of affected Android systems.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.