Logic Error Vulnerability in Android Framework's HeaderPrivacyIconsController
CVE-2025-48589
Currently unrated
What is CVE-2025-48589?
A logic error in the HeaderPrivacyIconsController.kt file of the Android Framework allows for the potential granting of permissions across user profiles. This flaw results in a local privilege escalation scenario without requiring additional execution permissions or user interaction, creating a significant security risk. Attackers exploiting this vulnerability could gain elevated privileges within the system.
Affected Version(s)
Android 16
Android 15
Android 14