CVE-2025-48581
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected products
- Apexd
- Google Android
- = 16.0
- CVSS 3.1
- 8.4 HIGH
- EPSS
- 0.2% (8th percentile)
- Weakness
- CWE-754
- NVD status
- Modified
- Published
- 2025-09-04
CVE-2025-48581 at NVD
4 known exploits for CVE-2025-48581
Proof-of-concept code and exploit modules indexed by Sploitus