
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48589 is a local privilege escalation vulnerability in Android affecting multiple functions of HeaderPrivacyIconsController.kt. A logic error in the code allows a low-privileged local attacker to grant permissions across user accounts without any user interaction. Affected versions include Android 13.0, 14.0, 15.0, and 16.0. It carries a CVSS v3.1 base score of 7.8 (High) and was publicly disclosed on December 8, 2025, as part of Google's December 2025 Android Security Bulletin (Android Bulletin).
The root cause is a logic error (CWE-269: Improper Privilege Management) in multiple functions within HeaderPrivacyIconsController.kt, a component of the Android framework (platform/frameworks/base). The flaw enables cross-user permission grants, meaning a process running under one user account can improperly escalate privileges into another user's context. Exploitation requires only local access with low privileges and no user interaction, making it straightforward for a malicious app already installed on the device to trigger. The fix was committed to the Android Open Source Project (AOSP) repository (AOSP Commit).
Successful exploitation allows an attacker with low-level local access to escalate privileges without requiring additional execution rights, potentially compromising system integrity, accessing sensitive confidential information belonging to other user profiles, and disrupting device functionality. The scope of impact spans confidentiality, integrity, and availability — all rated High — across Android 13 through 16 devices (Android Bulletin).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Android Bulletin). The EPSS score is extremely low at 0.000050, reflecting minimal near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
HeaderPrivacyIconsController.kt through the app, exploiting the cross-user permission grant logic error — no user interaction is required.logcat) involving HeaderPrivacyIconsController or cross-user permission changes without corresponding user-initiated actions.Google has released a patch as part of the December 2025 Android Security Bulletin (security patch level 2025-12-01). Users and administrators should apply the December 2025 Android security update immediately to all affected devices running Android 13, 14, 15, or 16. As a general precaution, restrict installation of apps from untrusted sources, enforce the principle of least privilege, and monitor for unusual permission changes on multi-user devices (Android Bulletin).
The vulnerability was covered as part of broader reporting on Google's December 2025 Android patch cycle, which addressed over 100 vulnerabilities. Security news outlets such as BeyondMachines and TheCyberThrone noted the patch release without specific focus on this CVE. No notable individual researcher commentary or significant social media discussion specific to CVE-2025-48589 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."