Home

Description

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

PUBLISHED Reserved 2025-05-22 | Published 2025-09-04 | Updated 2025-09-05 | Assigner google_android

Problem types

Elevation of privilege

Product status

Default status
unaffected

15
affected

14
affected

13
affected

References

android.googlesource.com/...1c2feffb6d64e669b956d59a6062b751

android.googlesource.com/...34cb3b02a66f6c241c0b9c9981998d6f

android.googlesource.com/...fad105da187b021fb762a66d37c9212a

android.googlesource.com/...8fce6ec4f7a1bf36f0ea3797805f00ce

android.googlesource.com/...225843ff3cc7d6bea05ae2f4db83b408

source.android.com/security/bulletin/2025-09-01

cve.org (CVE-2025-48548)

nvd.nist.gov (CVE-2025-48548)

Download JSON