CVE-2025-48584
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48584 is a local denial-of-service vulnerability in Android's NotificationManagerService.java that allows a low-privileged attacker to bypass per-package notification channel limits, causing resource exhaustion. It affects Android 16.0 and was publicly disclosed on December 8, 2025, as part of Google's December 2025 Android Security Bulletin. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) in multiple functions within NotificationManagerService.java. Android enforces per-package limits on notification channels to prevent abuse, but flaws in the enforcement logic allow a local application with low privileges to create channels beyond the intended cap, exhausting system resources. No user interaction is required, and no elevated privileges are needed beyond a standard app installation context. A patch commit addressing the issue is available in the Android platform frameworks/base repository (Android Source Patch, Android Security Bulletin).

Impact

Successful exploitation leads to local denial of service, specifically rendering the notification subsystem unresponsive or causing broader system resource exhaustion on the affected Android 16.0 device. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local device; lateral movement or remote data exposure is not a concern with this vulnerability (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000050, reflecting minimal probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Security Bulletin).

Mitigation and workarounds

Google released a patch for this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01), targeting Android 16.0. The fix is available via the Android Open Source Project commit 08a0766708db2071d9b8b65abf40d7e8057daaa1. Users and administrators should apply the December 2025 Android security update to all affected devices as soon as possible. As an interim measure, restricting installation of untrusted applications and monitoring system resource utilization can reduce exposure (Android Security Bulletin, Android Source Patch).

Community reactions

The vulnerability was noted in routine coverage of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. No significant independent researcher commentary or notable social media discussion specific to CVE-2025-48584 has been identified, consistent with its medium severity and local-only attack vector (BeyondMachines).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management