PT-2025-49014 · Google · Android

Published

2025-12-01

·

Updated

2025-12-08

·

CVE-2025-48591

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the Android Framework component due to insufficient protection of system data. This could allow an attacker to disclose protected information. The issue involves a missing permission check in multiple locations, potentially allowing unauthorized reading of files belonging to other users. Exploitation does not require additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

ASB-A-305710469
BDU:2025-15130
CVE-2025-48591

Affected Products

Android