
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48559 is an improper input validation vulnerability in Android's AppOpsService.java that allows a local attacker to add a large number of app operations, resulting in a local denial of service (DoS). It affects Android versions 13.0, 14.0, 15.0, and 16.0. The vulnerability was disclosed on September 4, 2025, as part of Google's Android Security Bulletin for September 2025. It carries a CVSS v3.1 base score of 5.5 (Medium), requiring only low privileges and no user interaction (Android Bulletin).
The vulnerability is rooted in improper input validation (CWE-20) within multiple functions of AppOpsService.java in the Android framework (platform/frameworks/base). An attacker with a low-privilege local account can exploit this by submitting crafted input that causes the service to register an excessive number of app operations, exhausting system resources. No additional execution privileges or user interaction are required, and attack complexity is low. The patch was committed to the Android Open Source Project (AOSP) repository (Android Bulletin, AOSP Patch).
Successful exploitation leads to a local denial of service condition on the affected Android device. An attacker can overwhelm the AppOpsService with a large volume of app operations, potentially causing system instability or unresponsiveness. There is no reported impact on confidentiality or integrity; the vulnerability is limited to availability (Android Bulletin).
Google has released patches for Android 13.0, 14.0, 15.0, and 16.0 as part of the September 2025 Android Security Bulletin (patch level 2025-09-01). Users and administrators should apply the latest Android security update immediately. As interim mitigations, restricting local system access, monitoring for unusual app operation activity, and applying the principle of least privilege for local users are recommended (Android Bulletin).
The September 2025 Android Security Bulletin received coverage from security news outlets and OEM vendors. Samsung announced its September 2025 security update incorporating these patches for Galaxy devices, and Huawei addressed the vulnerability in its October 2025 EMUI/HarmonyOS security update. CIS published an advisory noting multiple vulnerabilities in the Android OS patched in this bulletin (CIS Advisory, Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."