CVE 7.8 HIGH

CVE-2025-48594_CVE-2025-48594

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Basic Information

ID CVE-2025-48594
Source google_android
Published Dec 8, 2025 at 16:57
Modified Dec 11, 2025 at 15:03

Affected Product

Vendor Google
Product Android
Version 16
Affected Versions Google Android 16
Google Android 15
Google Android 14

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.