CVE-2025-48555
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48555 is a confused deputy vulnerability affecting multiple functions in NotificationStation.java within the Android Settings application, enabling cross-profile information disclosure and local privilege escalation. It affects Android versions 13.0, 14.0, 15.0, and 16.0. No additional execution privileges are required, and user interaction is not needed for exploitation. It carries a CVSS v3.1 base score of 7.8 (High) and was publicly disclosed on December 8, 2025, as part of Google's December 2025 Android Security Bulletin (Android Bulletin).

Technical details

The vulnerability is classified as CWE-441 (Unintended Proxy or Intermediary — 'Confused Deputy'), where multiple functions in NotificationStation.java fail to properly enforce profile boundaries, allowing a lower-privileged component to act on behalf of a higher-privileged one. An attacker with a low-privilege local account can exploit this flaw to access notification data or other sensitive information belonging to a different user profile on the same device. The patch was committed to the Android Settings package in the AOSP repository (AOSP Patch). No public proof-of-concept exploit code has been identified (Android Bulletin).

Impact

Successful exploitation allows a local attacker with low privileges to escalate privileges and access sensitive cross-profile information — such as notifications from a work or secondary user profile — without any user interaction. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read sensitive data, potentially modify profile-related state, and disrupt normal notification functionality. This is particularly relevant on devices using Android's managed profile or multi-user features, such as enterprise BYOD deployments (Android Bulletin).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The EPSS score is extremely low at 0.000050, reflecting minimal current exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least low-level privileges, limiting the attack surface compared to remote vulnerabilities (Android Bulletin).

Mitigation and workarounds

Google addressed this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the latest Android security update to all affected devices running Android 13, 14, 15, or 16. Enterprise administrators should enforce strict access controls between user profiles and ensure managed devices are enrolled in a mobile device management (MDM) solution that enforces timely patch compliance. No configuration-based workaround is available; patching is the only remediation (Android Bulletin, AOSP Patch).

Community reactions

The vulnerability was noted in coverage of Google's December 2025 Android patch cycle, which addressed over 100 vulnerabilities. Security news outlets including BeyondMachines and TheCyberThrone covered the broader bulletin, and GrapheneOS released an updated build incorporating the fix shortly after disclosure. No significant individual researcher commentary or social media discussion specific to CVE-2025-48555 has been identified (Android Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management