Desynchronization Vulnerability in NotificationChannel.java Affects Android Framework
CVE-2025-48556
7.3HIGH
What is CVE-2025-48556?
A vulnerability exists in the Android Framework's NotificationChannel.java where flaws in input validation can lead to a desynchronization from persistence. This flaw may allow a local attacker to escalate privileges without requiring additional execution permissions. User interaction is necessary for the attack to be successful, creating a potential security risk within the affected Android installations.
Affected Version(s)
Android 16
Android 15