Persistent Denial of Service in Android Device Policy Manager Service
CVE-2025-48554
Currently unrated
What is CVE-2025-48554?
The vulnerability arises in the handlePackagesChanged method of DevicePolicyManagerService.java, where a logic error may allow an attacker to create a persistent denial of service condition. This issue can be exploited locally, requiring user interaction, to disrupt device policies without needing additional execution privileges. Proper updates and patches are essential to mitigate this security risk.
Affected Version(s)
Android 16
Android 15
Android 14