CVE-2025-48633: Android Framework Information Disclosure Vulnerability
Android Framework contains an unspecified vulnerability that allows for information disclosure.
Other sources
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48633?
CVE-2025-48633 is classified as a high-severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2025-48633?
To mitigate CVE-2025-48633, update the Android Framework to the latest stable version provided by your device manufacturer.
What type of vulnerability is CVE-2025-48633?
CVE-2025-48633 is an unspecified vulnerability in the Android Framework that allows for information disclosure.
Who is affected by CVE-2025-48633?
CVE-2025-48633 affects devices running the Android Framework that have not been updated to address this vulnerability.
Can CVE-2025-48633 be exploited remotely?
Yes, CVE-2025-48633 may be exploitable remotely, allowing attackers to access sensitive information without physical access to the device.