CVE-2025-48604
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:17
- Zuletzt bearbeitet 08.12.2025 21:15:58
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2025-48607
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:17
- Zuletzt bearbeitet 08.12.2025 21:15:59
In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploit...
CVE-2025-48610
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:17
- Zuletzt bearbeitet 08.12.2025 21:15:59
In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...
CVE-2025-48612
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:17
- Zuletzt bearbeitet 08.12.2025 19:40:36
In multiple locations, there is a possible way for an application on a work profile to set the main user's default NFC payment setting due to improper input validation. This could lead to local escalation of privilege with no additional execution pri...
CVE-2025-48614
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:17
- Zuletzt bearbeitet 08.12.2025 21:16:00
In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This could lead to physical denial of service with no additional execution privileges needed. User ...
CVE-2025-48589
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:16
- Zuletzt bearbeitet 10.12.2025 19:43:36
In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use...
CVE-2025-48590
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:16
- Zuletzt bearbeitet 10.12.2025 19:44:09
In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to resource exhaustion. This could lead to local denial of service with no additional ex...
CVE-2025-48591
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:16
- Zuletzt bearbeitet 09.12.2025 21:38:50
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVE-2025-48592
- EPSS 0.05%
- Veröffentlicht 08.12.2025 17:16:16
- Zuletzt bearbeitet 08.12.2025 21:15:56
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...
CVE-2025-48594
- EPSS 0.01%
- Veröffentlicht 08.12.2025 17:16:16
- Zuletzt bearbeitet 11.12.2025 15:15:47
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional executio...