
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48543 is a use-after-free vulnerability in the Android Runtime (ART) that allows a low-privileged local attacker to escape the Chrome sandbox and escalate privileges to compromise the Android system_server process. Disclosed on September 4, 2025, as part of Google's September 2025 Android Security Bulletin, it affects Android versions 13.0, 14.0, 15.0, and 16.0. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Android Bulletin, CISA KEV).
The vulnerability is classified as CWE-416 (Use After Free) and exists in multiple locations within the Android Runtime (ART) framework. By exploiting a freed memory reference in ART, an attacker operating within the Chrome sandbox can trigger memory corruption to gain code execution in the context of system_server, effectively escaping the sandbox isolation boundary. The attack vector is local, requires only low privileges, has low attack complexity, and requires no user interaction, with a changed scope indicating cross-privilege-boundary impact. A patch was committed to the Android ART source at android.googlesource.com/platform/art/+/444fc40dfb04d2ec5f74c443ed3a4dd45d3131f2, and a technical write-up is available from ZeroPath (ZeroPath Blog, Android Bulletin).
Successful exploitation grants an attacker system-level code execution on the affected Android device, enabling complete device compromise including access to sensitive user data, credentials, and communications. The privilege escalation from a sandboxed Chrome renderer to system_server allows the attacker to bypass Android's security model, potentially enabling persistent access, surveillance, and lateral movement to other services or accounts on the device. All confidentiality, integrity, and availability impacts are rated High, and the changed scope means the compromise extends beyond the initially compromised component (CISA KEV, Feedly).
system_server privileges, granting system-level access to the device, enabling installation of spyware, credential theft, or persistent backdoor deployment (ZeroPath Blog, Google TI Blog).system_server exhibiting anomalous behavior such as spawning shell processes or accessing sensitive APIs outside normal patterns.logcat) showing ART crashes, memory corruption errors, or unexpected JNI exceptions; system_server logs indicating privilege changes or unusual IPC calls..so files), or configuration files in system directories; new or modified files in /data/local/tmp or other writable system paths.Google released patches in the September 1, 2025 Android Security Bulletin; users should update their Android devices to the security patch level of 2025-09-01 or later to remediate this vulnerability (Android Bulletin). Samsung and other OEMs have also released corresponding September 2025 security updates for their devices. CISA mandates that federal agencies apply mitigations per vendor instructions by September 25, 2025, per BOD 22-01 (CISA KEV). Organizations should enforce mandatory security update deployment policies for all Android devices in their environment; devices that cannot receive the patch (e.g., end-of-life Android versions) should be considered for replacement or network isolation.
Google's September 2025 Android Security Bulletin, which patched over 120 vulnerabilities including CVE-2025-48543, received significant media attention given the active exploitation of two zero-days. Forbes reported that approximately 1 billion older Android phones may not receive the fix, highlighting the fragmented Android update ecosystem (Forbes). SecurityWeek, BleepingComputer, HelpNetSecurity, and The Register all covered the active exploitation and CISA KEV listing (SecurityWeek, HelpNetSecurity). Google's Threat Intelligence Group subsequently published a report linking the vulnerability to Intellexa's Predator spyware, drawing further attention from the security research community (Google TI Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."