PT-2025-43479 · Google · Android

Published

2025-10-23

·

Updated

2025-12-08

·

CVE-2025-48592

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the Framework component of Android operating systems related to insufficient protection of service data. Exploitation of this issue may allow an attacker to disclose protected information. A potential out-of-bounds read exists due to a heap buffer overflow within the initDecoder function of C2SoftDav1dDec.cpp, which could lead to remote information disclosure without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Information Disclosure

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ASB-A-427113482
BDU:2025-15140
CVE-2025-48592

Affected Products

Android