CVE-2025-48576
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48576 is a local denial-of-service vulnerability in Android's NotificationManagerService.java, specifically within the updateNotificationChannelGroupFromPrivilegedListener method, caused by uncontrolled resource consumption (CWE-400). A low-privileged local attacker can trigger permanent denial of service through resource exhaustion without requiring user interaction. Affected versions include Android 13.0, 14.0, 15.0, and 16.0. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin). The vulnerability was publicly disclosed via the Android Security Bulletin dated December 1, 2025, and registered in NVD on December 8, 2025.

Technical details

The root cause is uncontrolled resource consumption (CWE-400) in the updateNotificationChannelGroupFromPrivilegedListener method of NotificationManagerService.java within the Android framework. An attacker with low-privilege local access can repeatedly invoke this method in a way that exhausts system resources, leading to a permanent denial-of-service condition. No elevated privileges or user interaction are required, making the attack surface accessible to any installed low-privilege application. The fix is available in the Android open-source repository (AOSP Patch).

Impact

Successful exploitation results in a permanent denial-of-service condition on the affected Android device, rendering it unresponsive or requiring a reboot. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability. The scope is limited to the local device, with no evidence of lateral movement potential or data exposure risk (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at 0.000050, reflecting minimal near-term exploitation probability. Exploitation requires only low-privilege local access with no user interaction, but the limited impact (local DoS only) reduces attacker incentive (Android Security Bulletin).

Mitigation and workarounds

Google has released patches for Android 13.0, 14.0, 15.0, and 16.0 via the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the latest Android security update immediately. The source-level fix is available in the AOSP repository (AOSP Patch). As a secondary measure, restricting installation of untrusted low-privilege applications and monitoring system resource consumption can reduce exposure until patching is complete (Android Security Bulletin).

Community reactions

Coverage of CVE-2025-48576 has been limited to routine security patch roundups. Security news outlets such as BeyondMachines and TheCyberThrone covered the broader December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities, without singling out this specific CVE. No notable researcher commentary or significant social media discussion specific to this vulnerability has been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72898CRITICAL10
  • NixOS logoNixOS
  • metabase
YesYesAug 10, 2026
CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-sqlite-debuginfo
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-odbc
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util-mysql
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management