Permissions Bypass Vulnerability in Android Framework
CVE-2025-48572

7.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

Badges

📰 News Worthy

What is CVE-2025-48572?

CVE-2025-48572 is a permissions bypass vulnerability found in the Android Framework, developed by Google. This vulnerability allows unintended activities to be launched from the background without proper permissions, compromising the security protocols within the Android operating system. Such a flaw could allow an unauthorized user to escalate their privileges locally, enabling them to perform actions typically restricted to higher-privilege applications or services. Importantly, the exploitation of this vulnerability does not require user interaction, which raises the stakes for affected systems as this could facilitate unauthorized access with minimal effort.

Potential impact of CVE-2025-48572

  1. Local Privilege Escalation: The most significant risk posed by this vulnerability is the potential for local privilege escalation. Attackers can exploit this weakness to gain unauthorized access to sensitive data or system functions, effectively bypassing standard security controls.

  2. Exploitation Without User Interaction: The fact that user interaction is unnecessary for exploitation means that malware or malicious applications could execute background operations without alerting the user, making it especially dangerous for device owners.

  3. Wider Attack Surface for Malicious Actors: By exploiting this vulnerability, attackers could potentially create further security breaches within the Android ecosystem. This could lead to larger-scale attacks, jeopardizing not just individual devices but also the broader network those devices connect to, including enterprise environments.

Affected Version(s)

Android 16

Android 15

Android 14

News Articles

CVE-2025-48633 and CVE-2025-48572: Android Framework Information Disclosure and Privilege Escalation Vulnerabilities Exploited in the Wild | SOC Prime

Explore details for CVE-2025-48633 and CVE-2025-48572, high-severity Android Framework vulnerabilities, with a deep analysis on our SOC Prime blog.

4 days ago

Google fixes Android vulnerabilities "under targeted exploitation" (CVE-2025-48633, CVE-2025-48572) - Help Net Security

Google patches Android vulnerabilities, including CVE-2025-48633 and CVE-2025-48572, which "may be under limited, targeted exploitation".

5 days ago

Google Patches Android 0-Day Vulnerabilities Exploited in the Wild

The vulnerabilities, disclosed in the December 2025 Android Security Bulletin, affect multiple Android versions

1 week ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 📰

    First article discovered by Cyber Press

  • Vulnerability Reserved

.
CVE-2025-48572 : Permissions Bypass Vulnerability in Android Framework