CVE-2025-48595: Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Other sources
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48595?
CVE-2025-48595 has a severity score of 8.4, indicating a high level of risk.
What is CVE-2025-48595 about?
CVE-2025-48595 refers to an integer overflow vulnerability in the Android Framework that can lead to local privilege escalation.
How do I fix CVE-2025-48595?
To fix CVE-2025-48595, apply mitigations as per vendor instructions and consider following the applicable BOD 22-01 guidance for cloud services.
Is CVE-2025-48595 actively exploited?
Yes, CVE-2025-48595 is actively exploited as it is listed in the KEV (Known Exploited Vulnerabilities) database.
What are the consequences of CVE-2025-48595?
The exploitation of CVE-2025-48595 can allow attackers to execute arbitrary code, leading to local privilege escalation on affected Android devices.