In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

cve CVE-2025-48640 1 source, 1 claim · Watch

NVD writes:
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. En múltiples ubicaciones, existe una posible aprobación de emparejamiento de entrada de clave de acceso de terceros debido a la ausencia de una verificación de permisos. Esto podría conducir a una escalada de privilegios remota (próxima/adyacente) sin necesidad de privilegios de ejecución adicionales. No se nece… the claim

What it is to other things

affectsgoogle/android
NVD
made_bygoogle
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD8
receipt
Source
NVD
Its words
8.0
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "17"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples ubicaciones, existe una posible aprobación de emparejamiento de entrada de clave de acceso de terceros debido a la ausencia de una verificación de permisos. Esto podría conducir a una escalada de privilegios remota (próxima/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48640",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48640",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-17T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-17T13:19:14.040",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/docs/security/bulletin/android-17"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDAndroid
receipt
Source
NVD
Its words
Android
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "17"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples ubicaciones, existe una posible aprobación de emparejamiento de entrada de clave de acceso de terceros debido a la ausencia de una verificación de permisos. Esto podría conducir a una escalada de privilegios remota (próxima/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48640",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48640",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-17T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-17T13:19:14.040",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/docs/security/bulletin/android-17"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "17"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples ubicaciones, existe una posible aprobación de emparejamiento de entrada de clave de acceso de terceros debido a la ausencia de una verificación de permisos. Esto podría conducir a una escalada de privilegios remota (próxima/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48640",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48640",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-17T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-17T13:19:14.040",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/docs/security/bulletin/android-17"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGoogle
receipt
Source
NVD
Its words
Google
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Android",
            "vendor": "Google",
            "versions": [
              {
                "status": "affected",
                "version": "17"
              }
            ]
          }
        ],
        "source": "security@android.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "E3D15FD9-304E-4270-81C7-C8D9024D457D",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
      },
      {
        "lang": "es",
        "value": "En múltiples ubicaciones, existe una posible aprobación de emparejamiento de entrada de clave de acceso de terceros debido a la ausencia de una verificación de permisos. Esto podría conducir a una escalada de privilegios remota (próxima/adyacente) sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación."
      }
    ],
    "id": "CVE-2025-48640",
    "lastModified": "2026-09-30T16:10:00.223",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-48640",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-17T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-17T13:19:14.040",
    "references": [
      {
        "source": "security@android.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://source.android.com/docs/security/bulletin/android-17"
      }
    ],
    "sourceIdentifier": "security@android.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
zetlyn/cve-nvd · 2026-06-17
cvss 8 product Android status Analyzed vendor Google source