Contacts Leakage Vulnerability in Android Telephony Services
CVE-2025-48586

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48586?

A vulnerability exists in the onActivityResult method of EditFdnContactScreen.java within Android Telephony Services. This flaw allows potential unauthorized access to contacts stored in the work profile due to a confused deputy problem. As a result, attackers could exploit this vulnerability to gain access to sensitive information without requiring additional permissions or user interaction.

Affected Version(s)

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48586 : Contacts Leakage Vulnerability in Android Telephony Services