Input Validation Flaw in Android's Package Manager Service
CVE-2025-48538

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48538?

An input validation vulnerability in the PackageManagerService allows for the potential concealment of a critical system package. This flaw can lead to a local denial of service without requiring additional execution privileges. Exploitation of this vulnerability does not require user interaction, thus increasing the risk of unauthorized system behavior.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48538 : Input Validation Flaw in Android's Package Manager Service