Local Escalation of Privilege in Voice Interaction Manager Service by Android
CVE-2025-48620
Currently unrated
What is CVE-2025-48620?
A logic error in the onSomePackagesChanged method of VoiceInteractionManagerService.java allows a third-party application's component name to remain persistent even after the application is uninstalled. This flaw enables potential local escalation of privilege without requiring additional execution privileges or user interactions, which may compromise the integrity of a user's device by enabling unauthorized access to sensitive areas.
Affected Version(s)
Android 16
Android 15
Android 14