Path Traversal Vulnerability in Android Wear Bugreport Content Provider
CVE-2025-48636
8.4HIGH
What is CVE-2025-48636?
In the openFile method of BugreportContentProvider.java within Android Wear, a path traversal vulnerability permits unauthorized reading and writing of files. This flaw can result in local privilege escalation, as it does not require additional execution privileges for exploitation. The vulnerability does not necessitate user interaction, which further heightens the security risk.
Affected Version(s)
Android 16