Local Escalation of Privilege in Voice Interaction Manager Service by Android
CVE-2025-48620

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48620?

A logic error in the onSomePackagesChanged method of VoiceInteractionManagerService.java allows a third-party application's component name to remain persistent even after the application is uninstalled. This flaw enables potential local escalation of privilege without requiring additional execution privileges or user interactions, which may compromise the integrity of a user's device by enabling unauthorized access to sensitive areas.

Affected Version(s)

Android 16

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48620 : Local Escalation of Privilege in Voice Interaction Manager Service by Android