Cross-User Image Leak in Android PrintManagerService
CVE-2025-48628

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 December 2025

What is CVE-2025-48628?

A security concern exists in the PrintManagerService of Android, where the validateIconUserBoundary function can inadvertently expose images between users. This flaw could allow a potential local escalation of privilege without requiring additional execution privileges. Notably, the exploitation of this vulnerability does not necessitate user interaction, making it a significant risk for Android device security.

Affected Version(s)

Android 16

Android 15

Android 14

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48628 : Cross-User Image Leak in Android PrintManagerService