7.8

CVE-2025-48540

In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Android Version 13.0
Google ≫ Android Version 14.0
Google ≫ Android Version 15.0
Google ≫ Android Version 16.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.008
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://source.android.com/security/bulletin/2025-09-01
Vendor Advisory
https://android.googlesource.com/platform/frameworks/native/+/570e2d6e29ee10879150f868913c285a45a936b1
Patch
https://android.googlesource.com/platform/frameworks/native/+/ba4ea3598e6dcea4b7b2202f4cec11eb1d85c2a7
Patch
https://android.googlesource.com/platform/frameworks/native/+/7fb4755c9d93bf75de13f2bc458fbbb547a79dd6
Patch