CVE-2025-48535
- EPSS 0.05%
- Veröffentlicht 04.09.2025 18:34:15
- Zuletzt bearbeitet 05.09.2025 19:05:25
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege wit...
CVE-2025-48534
- EPSS 0.05%
- Veröffentlicht 04.09.2025 18:34:14
- Zuletzt bearbeitet 05.09.2025 19:05:33
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed...
CVE-2025-48532
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:13
- Zuletzt bearbeitet 05.09.2025 19:10:54
In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inte...
CVE-2025-48531
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:12
- Zuletzt bearbeitet 05.09.2025 19:10:48
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...
CVE-2025-48529
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:11
- Zuletzt bearbeitet 05.09.2025 19:10:30
In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n...
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:10
- Zuletzt bearbeitet 05.09.2025 19:10:19
In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48527
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:09
- Zuletzt bearbeitet 05.09.2025 19:10:11
In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:07
- Zuletzt bearbeitet 05.09.2025 19:15:31
In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional exec...
CVE-2025-48524
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:06
- Zuletzt bearbeitet 08.09.2025 14:04:43
In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...
CVE-2025-48523
- EPSS 0.01%
- Veröffentlicht 04.09.2025 18:34:05
- Zuletzt bearbeitet 05.09.2025 19:15:19
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ...