PT-2025-35654 · Google · Android Runtime

Publicado

2025-09-01

·

Atualizado

2025-12-07

·

CVE-2025-48543

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android Runtime (affected versions not specified)
Description The Android Runtime contains a use-after-free vulnerability that allows for escaping the Chrome sandbox to attack the Android system server. Successful exploitation could lead to local escalation of privilege without requiring additional execution privileges or user interaction. This vulnerability is under active exploitation, with federal agencies required to patch by September 25th. Approximately an unspecified number of devices are potentially affected worldwide.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ASB-A-421834866
BDU:2025-10824
CVE-2025-48543

Produtos afetados

Android Runtime