CVE-2025-48582
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48582 is a local privilege escalation vulnerability in Google Android affecting versions 14.0, 15.0, and 16.0 (including QPR2 beta releases). The flaw allows an attacker to delete media files without holding the MANAGE_EXTERNAL_STORAGE permission by exploiting an intent redirect. No user interaction or additional execution privileges are required. It was published on March 2, 2026, and carries a CVSS v3.1 base score of 8.4 (High) (Android Security Bulletin, Red Hat CVE).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access / 'Link Following'), manifesting as an intent redirect in multiple Android framework locations. A malicious local application can craft an intent that is redirected to a privileged component, causing it to perform media deletion operations on behalf of the attacker without the MANAGE_EXTERNAL_STORAGE permission check being enforced. This attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it straightforward to trigger from any installed application on the device (Android Security Bulletin, Red Hat CVE).

Impact

Successful exploitation allows a local attacker to delete media files on the device without the required storage permission, resulting in high impacts to confidentiality, integrity, and availability. An attacker could destroy or manipulate user media data, potentially as a precursor to further privilege escalation or data exfiltration. The scope is limited to the affected device (S:U), but the combination of no required privileges and no user interaction makes this a significant local threat on unpatched Android 14, 15, and 16 devices (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is extremely low at 0.000030, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Install malicious app: An attacker installs a malicious application on the target Android device (14.0, 15.0, or 16.0) that does not hold the MANAGE_EXTERNAL_STORAGE permission.
  2. Craft malicious intent: The malicious app constructs a specially crafted Android intent targeting a vulnerable system component that handles media deletion.
  3. Trigger intent redirect: The app sends the crafted intent, which is improperly redirected by the Android framework to a privileged component responsible for media management.
  4. Bypass permission check: Due to the intent redirect flaw (CWE-59), the privileged component executes the media deletion operation without verifying that the originating app holds MANAGE_EXTERNAL_STORAGE.
  5. Delete media files: The attacker achieves unauthorized deletion of media files on the device, with potential for further data manipulation or privilege escalation (Android Security Bulletin).

Indicators of compromise

  • Logs: Android system logs (logcat) showing unexpected media deletion events originating from an application that does not hold MANAGE_EXTERNAL_STORAGE; intent dispatch logs showing redirected intents to privileged media management components.
  • File System: Unexplained disappearance of media files (images, videos, audio) from external or shared storage without user-initiated deletion.
  • Process/Application Behavior: Applications without storage management permissions triggering media-related system service calls; unusual activity from third-party apps in Android's ActivityManager or MediaProvider logs.

Mitigation and workarounds

Google has released patches addressing CVE-2025-48582 in the Android Security Bulletin for 2026-03-01, covering Android 14.0, 15.0, and 16.0. Users and administrators should apply the March 2026 security patch level (2026-03-01 or later) to all affected devices as soon as it is available from their device manufacturer. As a workaround, restricting physical and logical access to devices and avoiding installation of untrusted applications reduces exposure. Samsung and Huawei have also incorporated these fixes in their respective March/April 2026 security updates (Android Security Bulletin, CIS Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for privilege escalation, including CVE-2025-48582 (CIS Advisory). Samsung and Huawei both referenced the vulnerability in their respective March and April 2026 security bulletins. Community and social media discussion has been limited, with no significant researcher commentary or media coverage beyond standard vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68981HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-69153MEDIUM6.3
  • JavaScript logoJavaScript
  • unleash-server
NoYesAug 03, 2026
CVE-2026-68979MEDIUM5.9
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-64640MEDIUM5.3
  • Python logoPython
  • polaris
NoYesAug 06, 2026
CVE-2026-68980LOW2.3
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management