Contacts Leakage Vulnerability in Android Telephony Services
CVE-2025-48586
Currently unrated
What is CVE-2025-48586?
A vulnerability exists in the onActivityResult method of EditFdnContactScreen.java within Android Telephony Services. This flaw allows potential unauthorized access to contacts stored in the work profile due to a confused deputy problem. As a result, attackers could exploit this vulnerability to gain access to sensitive information without requiring additional permissions or user interaction.
Affected Version(s)
Android 16
Android 15