PT-2025-43496 · Unknown · Contentprovider.Java

Published

2025-10-23

·

Updated

2026-03-06

·

CVE-2025-48619

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ContentProvider.java (affected versions not specified)
Description An application with read-only access may be able to truncate files due to a logic error in the code within multiple functions of ContentProvider.java. This could lead to local escalation of privilege without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-414387646
CVE-2025-48619

Affected Products

Contentprovider.Java