Description
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CISA Known Exploited Vulnerability
Date added 2025-12-02 | Due date 2025-12-23
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Problem types
Elevation of privilege
Product status
16
15
14
13
References
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2025-48572
android.googlesource.com/...0330691f9c67dc023c09f4cd2fc59192
source.android.com/security/bulletin/2025-12-01