Resource Exhaustion Vulnerability in Notification Manager Service for Android
CVE-2025-48584

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48584?

A significant vulnerability has been identified in the NotificationManagerService.java file, where several functions allow attackers to bypass per-package channel limits. This flaw can lead to resource exhaustion, potentially resulting in a local denial of service without the need for elevated execution privileges. Moreover, exploitation of this vulnerability does not require user interaction, making it particularly concerning for users and administrators of affected Android devices.

Affected Version(s)

Android 16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48584 : Resource Exhaustion Vulnerability in Notification Manager Service for Android