CVE-2025-48583 is a high-severity local escalation of privilege vulnerability affecting Google Android, stemming from a logic error in multiple functions of BaseBundle.java that allows for arbitrary code execution. With a CVSS score of 7.8, this vulnerability requires no user interaction or additional execution privileges for exploitation, posing a significant risk of full compromise (confidentiality, integrity, availability). Currently, there is no public exploit intelligence, Metasploit modules, or Nuclei templates available, and it has received minimal community discussion or media coverage, indicating it is not actively exploited or widely known at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0CPE matchmatch criteria | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.