
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48566 is a local privilege escalation vulnerability in the Android framework caused by improper input validation that allows a possible bypass of user profile boundaries via a forwarded intent. It affects Android versions 13.0, 14.0, 15.0, and 16.0. The vulnerability was disclosed in the December 2025 Android Security Bulletin (published December 1, 2025) and assigned a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).
The root cause is classified as CWE-20 (Improper Input Validation) and exists in multiple locations within the Android framework, specifically in platform/frameworks/base and platform/packages/modules/IntentResolver. An attacker exploits the flaw by crafting a forwarded intent that bypasses user profile boundary enforcement, allowing code to cross profile boundaries without proper authorization. The attack vector is local, requires only low privileges, and no user interaction is needed, making it exploitable by any app with basic execution access on the device (Android Security Bulletin).
Successful exploitation allows a local attacker to escalate privileges beyond their assigned user profile, achieving high confidentiality, integrity, and availability impact on the affected device. An attacker could access data belonging to other user profiles (e.g., work profiles), modify system state, or disrupt device availability — all without requiring additional execution privileges or user interaction. The vulnerability affects a broad range of Android devices running versions 13 through 16, representing a significant portion of the active Android ecosystem (Android Security Bulletin).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is very low at 0.0001, reflecting limited near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Security Bulletin).
logcat) showing unexpected cross-profile intent resolution events or IntentResolver errors involving profile boundary checks.Google released patches in the December 2025 Android Security Bulletin (security patch level 2025-12-01), with code fixes applied to platform/frameworks/base and platform/packages/modules/IntentResolver. Device owners and administrators should apply the December 2025 security update immediately. No configuration-based workaround is available; patching is the only effective remediation. Enterprise administrators should prioritize updating managed Android devices and monitor for devices that cannot receive the patch (Android Security Bulletin).
The vulnerability was covered as part of broader reporting on the December 2025 Android Security Bulletin, which addressed over 100 Android vulnerabilities. Security outlets including SOCRadar and BeyondMachines noted the scale of the December patch cycle. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2025-48566 has been identified (SOCRadar, BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."