CVE-2025-48629
- EPSS 0.08%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privile...
CVE-2025-48631
- EPSS 0.48%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for...
CVE-2025-48632
- EPSS 0.08%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional exe...
CVE-2025-48633
- EPSS 0.26%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges ne...
CVE-2025-48637
- EPSS 0.1%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati...
CVE-2025-48638
- EPSS 0.1%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat...
CVE-2025-48639
- EPSS 0.1%
- Veröffentlicht 08.12.2025 17:16:19
- Zuletzt bearbeitet 07.10.2026 20:10:01
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction...
CVE-2025-48615
- EPSS 0.11%
- Veröffentlicht 08.12.2025 17:16:18
- Zuletzt bearbeitet 07.10.2026 20:10:01
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...
CVE-2025-48618
- EPSS 0.13%
- Veröffentlicht 08.12.2025 17:16:18
- Zuletzt bearbeitet 07.10.2026 20:10:01
In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User intera...
CVE-2025-48620
- EPSS 0.09%
- Veröffentlicht 08.12.2025 17:16:18
- Zuletzt bearbeitet 07.10.2026 20:10:01
In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's component name to persist even after uninstalling due to a logic error in the code. This could lead to local escalation of privil...