
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48582 is a local privilege escalation vulnerability in Google Android affecting versions 14.0, 15.0, and 16.0 (including QPR2 beta releases). The flaw allows an attacker to delete media files without holding the MANAGE_EXTERNAL_STORAGE permission by exploiting an intent redirect. No user interaction or additional execution privileges are required. It was published on March 2, 2026, and carries a CVSS v3.1 base score of 8.4 (High) (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), manifesting as an intent redirect in multiple Android framework locations. A malicious local application can craft an intent that is redirected to a privileged component, causing it to perform media deletion operations on behalf of the attacker without the MANAGE_EXTERNAL_STORAGE permission check being enforced. This attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it straightforward to trigger from any installed application on the device (Android Security Bulletin, Red Hat CVE).
Successful exploitation allows a local attacker to delete media files on the device without the required storage permission, resulting in high impacts to confidentiality, integrity, and availability. An attacker could destroy or manipulate user media data, potentially as a precursor to further privilege escalation or data exfiltration. The scope is limited to the affected device (S:U), but the combination of no required privileges and no user interaction makes this a significant local threat on unpatched Android 14, 15, and 16 devices (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is extremely low at 0.000030, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
MANAGE_EXTERNAL_STORAGE permission.MANAGE_EXTERNAL_STORAGE.logcat) showing unexpected media deletion events originating from an application that does not hold MANAGE_EXTERNAL_STORAGE; intent dispatch logs showing redirected intents to privileged media management components.ActivityManager or MediaProvider logs.Google has released patches addressing CVE-2025-48582 in the Android Security Bulletin for 2026-03-01, covering Android 14.0, 15.0, and 16.0. Users and administrators should apply the March 2026 security patch level (2026-03-01 or later) to all affected devices as soon as it is available from their device manufacturer. As a workaround, restricting physical and logical access to devices and avoiding installation of untrusted applications reduces exposure. Samsung and Huawei have also incorporated these fixes in their respective March/April 2026 security updates (Android Security Bulletin, CIS Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for privilege escalation, including CVE-2025-48582 (CIS Advisory). Samsung and Huawei both referenced the vulnerability in their respective March and April 2026 security bulletins. Community and social media discussion has been limited, with no significant researcher commentary or media coverage beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."