Local Privilege Escalation in Android RemoteFillService
CVE-2025-48563

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 September 2025

What is CVE-2025-48563?

A vulnerability exists in the RemoteFillService.java within the Android operating system, where an insecure default value may trigger unintended background activities. This flaw allows for local escalation of privileges, meaning an attacker could potentially gain unauthorized access to sensitive functionalities of the device without the need for user interaction or elevated execution privileges. This risk underscores the importance of applying security updates and ensuring that default configurations are securely set.

Affected Version(s)

Android 16

Android 15

Android 14

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48563 : Local Privilege Escalation in Android RemoteFillService