
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48583 is a local privilege escalation vulnerability in Android's BaseBundle.java caused by a logic error in multiple functions. It affects Android versions 14.0, 15.0, and 16.0, and allows a local attacker with low privileges to execute arbitrary code without any user interaction. The vulnerability was disclosed on December 8, 2025, as part of Google's December 2025 Android Security Bulletin. It carries a CVSS v3.1 base score of 7.8 (High) (Android Bulletin).
The root cause is a logic error (CWE-840 or similar logic flaw) in multiple functions within BaseBundle.java, a core Android framework component responsible for handling key-value data bundles passed between application components. The flaw enables a locally executing attacker with low privileges to trigger arbitrary code execution, likely by crafting malicious bundle data that exploits the flawed logic path. No user interaction is required, and no additional privileges beyond a basic app context are needed for exploitation. A patch commit is available in the Android Open Source Project (AOSP) repository (AOSP Patch, Android Bulletin).
Successful exploitation grants an attacker local escalation of privilege, potentially achieving full control over the affected Android device's user context or system-level processes. The high confidentiality, integrity, and availability impact scores indicate that sensitive user data could be accessed or exfiltrated, device integrity could be compromised through unauthorized code execution, and system stability could be disrupted. Given that BaseBundle.java is a foundational framework component, exploitation could affect a broad range of inter-process communication pathways on the device (Android Bulletin).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Android Bulletin). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at 0.000050, reflecting minimal current exploitation probability. Qualys has added detection for this CVE (detection ID 610747), enabling vulnerability scanning on managed Android fleets (Feedly).
Google released a patch for CVE-2025-48583 in the December 2025 Android Security Bulletin (patch level 2025-12-01). The fix is available via the AOSP commit 02751bc65824a3877bdc21d865cd801b5e9f5e6c. Users and administrators should immediately apply the December 2025 Android security update to all affected devices running Android 14, 15, or 16. Organizations managing Android device fleets should use MDM solutions to enforce timely patch deployment and verify patch level compliance (Android Bulletin, AOSP Patch).
Coverage of CVE-2025-48583 has been limited to aggregator and security news sites reporting on the broader December 2025 Android patch batch, which addressed over 100 vulnerabilities. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified (BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."