
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48555 is a confused deputy vulnerability affecting multiple functions in NotificationStation.java within the Android Settings application, enabling cross-profile information disclosure and local privilege escalation. It affects Android versions 13.0, 14.0, 15.0, and 16.0. No additional execution privileges are required, and user interaction is not needed for exploitation. It carries a CVSS v3.1 base score of 7.8 (High) and was publicly disclosed on December 8, 2025, as part of Google's December 2025 Android Security Bulletin (Android Bulletin).
The vulnerability is classified as CWE-441 (Unintended Proxy or Intermediary — 'Confused Deputy'), where multiple functions in NotificationStation.java fail to properly enforce profile boundaries, allowing a lower-privileged component to act on behalf of a higher-privileged one. An attacker with a low-privilege local account can exploit this flaw to access notification data or other sensitive information belonging to a different user profile on the same device. The patch was committed to the Android Settings package in the AOSP repository (AOSP Patch). No public proof-of-concept exploit code has been identified (Android Bulletin).
Successful exploitation allows a local attacker with low privileges to escalate privileges and access sensitive cross-profile information — such as notifications from a work or secondary user profile — without any user interaction. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read sensitive data, potentially modify profile-related state, and disrupt normal notification functionality. This is particularly relevant on devices using Android's managed profile or multi-user features, such as enterprise BYOD deployments (Android Bulletin).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The EPSS score is extremely low at 0.000050, reflecting minimal current exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least low-level privileges, limiting the attack surface compared to remote vulnerabilities (Android Bulletin).
Google addressed this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the latest Android security update to all affected devices running Android 13, 14, 15, or 16. Enterprise administrators should enforce strict access controls between user profiles and ensure managed devices are enrolled in a mobile device management (MDM) solution that enforces timely patch compliance. No configuration-based workaround is available; patching is the only remediation (Android Bulletin, AOSP Patch).
The vulnerability was noted in coverage of Google's December 2025 Android patch cycle, which addressed over 100 vulnerabilities. Security news outlets including BeyondMachines and TheCyberThrone covered the broader bulletin, and GrapheneOS released an updated build incorporating the fix shortly after disclosure. No significant individual researcher commentary or social media discussion specific to CVE-2025-48555 has been identified (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."