CVE-2025-48524
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-04

Last updated on: 2025-09-08

Assigner: Android (associated with Google Inc. or Open Handset Alliance)

Description
In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-04
Last Modified
2025-09-08
Generated
2026-06-16
AI Q&A
2025-09-04
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
google android 13.0
google android 15.0
google android 16.0
google android 14.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a permission bypass in the isSystem method of WifiPermissionsUtil.java caused by a missing permission check. It allows an attacker to bypass intended permission restrictions.

Impact Analysis

The vulnerability could lead to a local denial of service (DoS) without requiring any additional execution privileges or user interaction.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-48524. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart