PT-2025-43495 · Google · Android

Published

2025-10-23

·

Updated

2025-12-09

·

CVE-2025-48618

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the Framework component of Android operating systems due to insufficient input validation. This could allow an attacker to escalate privileges. Specifically, the issue resides in the processLaunchBrowser function within CommandParamsFactory.java, where improper locking may allow browser interaction from the lockscreen. Exploitation does not require user interaction and could lead to physical escalation of privilege without needing additional execution privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Improper Locking

Weakness Enumeration

Related Identifiers

ASB-A-404254549
BDU:2025-15133
CVE-2025-48618

Affected Products

Android