PT-2025-48941 · Android · Android

Published

2025-08-28

·

Updated

2025-12-08

·

CVE-2025-48637

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description The Android operating system’s pKVM (protected Kernel-based Virtual Machine) virtualization technology contains synchronization errors when adding pages to the memory cache, resulting in a race condition. Exploitation may allow an attacker to gain elevated privileges. Multiple functions within mem protect.c are susceptible to an out-of-bounds write condition caused by an integer overflow, potentially leading to local privilege escalation without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Time Of Check To Time Of Use

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15116
CVE-2025-48637

Affected Products

Android