Persistent Denial of Service Vulnerability in Android Framework by Google
CVE-2025-48537

7.1HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48537?

A vulnerability exists in the Android Framework that allows for a persistent Denial of Service (DoS) due to improper input validation in multiple locations. This flaw can potentially enable local information disclosure without requiring any additional execution privileges. Importantly, user interaction is not necessary for the exploitation of this vulnerability, which could pose significant risks to device users. It is crucial for developers and users to be aware of this issue and apply necessary mitigations.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48537 : Persistent Denial of Service Vulnerability in Android Framework by Google