Privilege Escalation Vulnerability in Android Framework by Google
CVE-2025-48597
7.8HIGH
What is CVE-2025-48597?
This vulnerability allows an attacker to exploit the Android Framework through a tapjacking or overlay attack. By deceiving users into inadvertently granting permissions, the attacker can achieve local escalation of privileges without requiring any additional execution privileges or user interaction. This loophole poses significant security risks as it can lead to unauthorized access and control over sensitive features within the Android device. Users are advised to stay updated with security patches and monitor official updates from Google to mitigate this risk.
Affected Version(s)
Android 16
Android 15
Android 14