Logic Error in VPN Software Allowing Privilege Escalation
CVE-2025-48588

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48588?

A flaw exists in the 'startAlwaysOnVpn' method of the Vpn.java file, where a logic error allows for the potential disabling of always-on VPN functionality. This vulnerability poses a risk of local privilege escalation that can be exploited without requiring additional execution privileges or user interaction. Proper safeguards need to be implemented to prevent unauthorized access to sensitive network configurations.

Affected Version(s)

Android 15

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48588 : Logic Error in VPN Software Allowing Privilege Escalation