PT-2025-35935 · Android · Android

Published

2025-09-01

·

Updated

2025-11-16

·

CVE-2025-48539

CVSS v3.1

8.0

High

AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The issue is a critical zero-click Remote Code Execution (RCE) flaw that allows attackers to hijack Android devices via Wi-Fi or Bluetooth without any user interaction. Exploitation can occur with no additional execution privileges needed and within physical or network proximity. Successful exploitation could lead to full device access remotely through privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-406785684
BDU:2025-10997
CVE-2025-48539

Affected Products

Android