PT-2025-35935 · Android · Android
Published
2025-09-01
·
Updated
2025-11-16
·
CVE-2025-48539
CVSS v3.1
8.0
High
| AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android (affected versions not specified)
Description
The issue is a critical zero-click Remote Code Execution (RCE) flaw that allows attackers to hijack Android devices via Wi-Fi or Bluetooth without any user interaction. Exploitation can occur with no additional execution privileges needed and within physical or network proximity. Successful exploitation could lead to full device access remotely through privilege escalation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
LPE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android