CVE-2025-48645

All FrameworksAndroidCWE-269CVE-2025-48645

CVE-2025-48645

State: PUBLISHED · Published: 2026-03-02 · Updated: 2026-04-21 · Assigner: google_android
Description
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/48xxx/CVE-2025-48645.json