In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

cve CVE-2025-48589 1 source, 1 claim · Watch

NVD writes:
In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. En múltiples funciones de HeaderPrivacyIconsController.kt, existe una posible forma de conceder permisos entre usuarios debido a un error de lógica en el código. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del … the claim

What it is to other things

affectsgoogle/android
NVD
made_bygoogle
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              },
              {
                "status": "affected",
                "version": "13"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples funciones de HeaderPrivacyIconsController.kt, existe una posible forma de conceder permisos entre usuarios debido a un error de lógica en el código. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48589",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48589",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-09T04:55:59.766632Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-08T17:16:16.050",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Patch",
          "Product"
        ],
        "url": "https://android.googlesource.com/platform/frameworks/base/+/2aeba76a58c18f66502ecbba4c2e73a8d6e2928c"
      },
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/security/bulletin/2025-12-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Product
product
NVDAndroid
receipt
Source
NVD
Its words
Android
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              },
              {
                "status": "affected",
                "version": "13"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples funciones de HeaderPrivacyIconsController.kt, existe una posible forma de conceder permisos entre usuarios debido a un error de lógica en el código. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48589",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48589",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-09T04:55:59.766632Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-08T17:16:16.050",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Patch",
          "Product"
        ],
        "url": "https://android.googlesource.com/platform/frameworks/base/+/2aeba76a58c18f66502ecbba4c2e73a8d6e2928c"
      },
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/security/bulletin/2025-12-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              },
              {
                "status": "affected",
                "version": "13"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples funciones de HeaderPrivacyIconsController.kt, existe una posible forma de conceder permisos entre usuarios debido a un error de lógica en el código. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48589",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48589",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-09T04:55:59.766632Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-08T17:16:16.050",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Patch",
          "Product"
        ],
        "url": "https://android.googlesource.com/platform/frameworks/base/+/2aeba76a58c18f66502ecbba4c2e73a8d6e2928c"
      },
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/security/bulletin/2025-12-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGoogle
receipt
Source
NVD
Its words
Google
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "16"
              },
              {
                "status": "affected",
                "version": "15"
              },
              {
                "status": "affected",
                "version": "14"
              },
              {
                "status": "affected",
                "version": "13"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "879FFD0C-9B38-4CAA-B057-1086D794D469",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "2700BCC5-634D-4EC6-AB67-5B678D5F951D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "8538774C-906D-4B03-A3E7-FA7A55E0DA9E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "02882AB1-7993-47DD-84A0-8DF4272D85ED",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples funciones de HeaderPrivacyIconsController.kt, existe una posible forma de conceder permisos entre usuarios debido a un error de lógica en el código. Esto podría llevar a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48589",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48589",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-09T04:55:59.766632Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-08T17:16:16.050",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Patch",
          "Product"
        ],
        "url": "https://android.googlesource.com/platform/frameworks/base/+/2aeba76a58c18f66502ecbba4c2e73a8d6e2928c"
      },
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/security/bulletin/2025-12-01"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "NVD-CWE-noinfo"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
zetlyn/cve-nvd · 2025-12-08
cvss 7.8 product Android status Analyzed vendor Google source