CVE-2025-48573
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48573 is a local privilege escalation vulnerability in Android's MediaSessionRecord.java that allows a background application to launch a foreground service by abusing the Foreground Service (FGS) while-in-use mechanism. It affects Android versions 13.0, 14.0, 15.0, and 16.0. The vulnerability was disclosed on December 8, 2025, with a patch included in Google's December 2025 Android Security Bulletin. It carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin).

Technical details

The root cause lies in the sendCommand method of MediaSessionRecord.java, where insufficient enforcement of FGS while-in-use restrictions allows a background app to improperly launch a foreground service (CWE-250: Execution with Unnecessary Privileges). An attacker with a locally installed, low-privileged application can exploit this flaw without requiring additional execution privileges or any user interaction. The attack vector is local, with low attack complexity, making it straightforward to exploit once an attacker has a foothold on the device. A patch commit is publicly available on the Android Open Source Project (AOSP) repository (AOSP Patch, Android Security Bulletin).

Impact

Successful exploitation enables a locally installed malicious application to escalate its privileges by launching foreground services outside of normal Android restrictions, potentially gaining elevated access to system resources. This could allow an attacker to compromise system integrity, manipulate service availability, and potentially access or modify sensitive data on the device. The impact spans confidentiality, integrity, and availability — all rated High — across Android 13 through 16 (Android Security Bulletin).

Exploitability

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Android Security Bulletin). The EPSS score is extremely low at 0.000050, reflecting minimal current exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.

Mitigation and workarounds

Google has released a patch as part of the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the latest Android security update immediately to all affected devices running Android 13, 14, 15, or 16. As interim measures, organizations should monitor system logs for unusual foreground service activity and enforce strict application permission controls. The AOSP patch is available at the referenced commit (Android Security Bulletin, AOSP Patch).

Community reactions

The vulnerability received coverage in the context of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Samsung's security update for October 2025 was noted in community discussions, and GrapheneOS released a corresponding update. Security aggregators such as BeyondMachines and Hawk-Eye noted the bulletin's breadth, though CVE-2025-48573 itself did not generate significant standalone commentary (Android Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097CRITICAL9.1
  • NixOS logoNixOS
  • python3-samba-test
NoYesAug 20, 2026
CVE-2026-11861HIGH8.1
  • NixOS logoNixOS
  • samba-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • samba-test-libs-debuginfo
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • samba-ldb-ldap-modules-debuginfo
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management