
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48576 is a local denial-of-service vulnerability in Android's NotificationManagerService.java, specifically within the updateNotificationChannelGroupFromPrivilegedListener method, caused by uncontrolled resource consumption (CWE-400). A low-privileged local attacker can trigger permanent denial of service through resource exhaustion without requiring user interaction. Affected versions include Android 13.0, 14.0, 15.0, and 16.0. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin). The vulnerability was publicly disclosed via the Android Security Bulletin dated December 1, 2025, and registered in NVD on December 8, 2025.
The root cause is uncontrolled resource consumption (CWE-400) in the updateNotificationChannelGroupFromPrivilegedListener method of NotificationManagerService.java within the Android framework. An attacker with low-privilege local access can repeatedly invoke this method in a way that exhausts system resources, leading to a permanent denial-of-service condition. No elevated privileges or user interaction are required, making the attack surface accessible to any installed low-privilege application. The fix is available in the Android open-source repository (AOSP Patch).
Successful exploitation results in a permanent denial-of-service condition on the affected Android device, rendering it unresponsive or requiring a reboot. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability. The scope is limited to the local device, with no evidence of lateral movement potential or data exposure risk (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at 0.000050, reflecting minimal near-term exploitation probability. Exploitation requires only low-privilege local access with no user interaction, but the limited impact (local DoS only) reduces attacker incentive (Android Security Bulletin).
Google has released patches for Android 13.0, 14.0, 15.0, and 16.0 via the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the latest Android security update immediately. The source-level fix is available in the AOSP repository (AOSP Patch). As a secondary measure, restricting installation of untrusted low-privilege applications and monitoring system resource consumption can reduce exposure until patching is complete (Android Security Bulletin).
Coverage of CVE-2025-48576 has been limited to routine security patch roundups. Security news outlets such as BeyondMachines and TheCyberThrone covered the broader December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities, without singling out this specific CVE. No notable researcher commentary or significant social media discussion specific to this vulnerability has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."