CVE-2025-48570
Activity Launch Vulnerability in PipTaskOrganizer
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in multiple functions of the PipTaskOrganizer.java file, where there is a possibility to launch an activity from the background due to a confused deputy problem.
This means that an attacker can exploit the system to perform actions they normally wouldn't be allowed to, by tricking the system into misusing its privileges.
No additional execution privileges or user interaction are needed to exploit this vulnerability.
How can this vulnerability impact me? :
The vulnerability can lead to a local escalation of privilege, allowing an attacker to perform actions with higher privileges than they should have.
Since exploitation does not require user interaction or additional privileges, it could be used to compromise the security of the affected system silently.