Logic Error in VPN Software Allowing Privilege Escalation
CVE-2025-48588
Currently unrated
What is CVE-2025-48588?
A flaw exists in the 'startAlwaysOnVpn' method of the Vpn.java file, where a logic error allows for the potential disabling of always-on VPN functionality. This vulnerability poses a risk of local privilege escalation that can be exploited without requiring additional execution privileges or user interaction. Proper safeguards need to be implemented to prevent unauthorized access to sensitive network configurations.
Affected Version(s)
Android 15
Android 14
Android 13