Input Validation Flaw in Android's Package Manager Service
CVE-2025-48538
5.5MEDIUM
What is CVE-2025-48538?
An input validation vulnerability in the PackageManagerService allows for the potential concealment of a critical system package. This flaw can lead to a local denial of service without requiring additional execution privileges. Exploitation of this vulnerability does not require user interaction, thus increasing the risk of unauthorized system behavior.
Affected Version(s)
Android 16
Android 15
Android 14