CVE-2025-48633: Android Framework Information Disclosure Vulnerability
Published Dec 1, 2025
·Updated
Android Framework contains an unspecified vulnerability that allows for information disclosure.
Affected Software
6 affected components
Android Framework
Google Android
Google Android=13.0
Google Android=14.0
Google Android=15.0
Google Android=16.0
Remediation
Information
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Event History
Dec 1, 2025
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Dec 2, 2025
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
News Published
via BleepingComputer·02:36 PM
News Published
via BleepingComputer·02:38 PM
News Published
via The Register·06:47 PM
News Published
via The Register·06:52 PM
Dec 4, 2025
News Published
via ZDNet·03:00 PM
News Published
via ZDNet·03:35 PM
Dec 8, 2025
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityAffected Software
Mar 3, 2026
News Published
via BleepingComputer·08:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-48633?
CVE-2025-48633 is classified as a high-severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2025-48633?
To mitigate CVE-2025-48633, update the Android Framework to the latest stable version provided by your device manufacturer.
3
What type of vulnerability is CVE-2025-48633?
CVE-2025-48633 is an unspecified vulnerability in the Android Framework that allows for information disclosure.
4
Who is affected by CVE-2025-48633?
CVE-2025-48633 affects devices running the Android Framework that have not been updated to address this vulnerability.
5
Can CVE-2025-48633 be exploited remotely?
Yes, CVE-2025-48633 may be exploitable remotely, allowing attackers to access sensitive information without physical access to the device.