Cross User Media Read Vulnerability in Android by Google
CVE-2025-48608

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48608?

A vulnerability exists in the isValidMediaUri function within the SettingsProvider.java of Android, where a lack of permission checks can permit unauthorized access to media, potentially leading to local information disclosures. This occurs without the need for user interaction or additional execution privileges, making it a serious concern for user privacy.

Affected Version(s)

Android 16-qpr2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48608 : Cross User Media Read Vulnerability in Android by Google