Local Denial of Service Vulnerability in AppOpsService by Android
CVE-2025-48559

5.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48559?

A vulnerability in the AppOpsService component of Android results from improper input validation within several functions of AppOpsService.java. This flaw allows attackers to manipulate app operations, potentially causing a local denial of service without requiring any elevated privileges or user interaction. The issue poses a risk as it can be exploited without the need for remote access, highlighting the importance of robust input validation mechanisms.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48559 : Local Denial of Service Vulnerability in AppOpsService by Android