PT-2025-49580 · Google · Android

Published

2025-12-08

·

Updated

2025-12-08

·

CVE-2025-48606

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android (affected versions not specified)
Description A flaw exists in the preparePackage function within InstallPackageHelper.java that may allow an application to install in a hidden state without providing a means for uninstallation. This is due to a logic error in the code. Exploitation does not require user interaction and can lead to local escalation of privilege without needing additional execution privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-48606

Affected Products

Android