CVE-2025-48563
BaseFortify
Publication date: 2025-09-04
Last updated on: 2025-09-08
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 13.0 | |
| android | 15.0 | |
| android | 16.0 | |
| android | 14.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-453 | The product, by default, initializes an internal variable with an insecure or less secure value than is possible. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs in the onNullBinding method of RemoteFillService.java, where an insecure default value can cause a background activity to launch unexpectedly. This flaw allows a local user to escalate their privileges without needing any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The vulnerability can allow a local attacker to escalate their privileges on the affected system, potentially gaining higher access rights than intended. This could lead to unauthorized actions or access to sensitive parts of the system.