
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48590 is a local denial-of-service vulnerability in Android's AppOpsService.java that allows a malicious app to prevent users from dialing emergency services under limited circumstances via resource exhaustion. The flaw resides in the verifyAndGetBypass method and affects Android versions 13, 14, 15, and 16. No elevated privileges are required, and user interaction is not needed for exploitation. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).
The root cause is uncontrolled resource consumption (CWE-400) within the verifyAndGetBypass method of AppOpsService.java in the Android framework. A low-privileged local app can trigger resource exhaustion through this method, which under certain conditions prevents the telephony stack from completing emergency call setup. The attack vector is local, requires only low privileges, and no user interaction, making it exploitable by any installed app without special permissions. The patch was committed to the Android Open Source Project (AOSP) frameworks/base repository (AOSP Patch, Android Security Bulletin).
Successful exploitation results in a local denial-of-service condition specifically targeting emergency call functionality, with high availability impact and no confidentiality or integrity impact. A malicious app installed on the device could, under limited circumstances, exhaust resources in the AppOps service and block the user from placing emergency calls (e.g., 911, 112), posing a direct risk to user safety. There is no evidence of lateral movement potential or data exposure associated with this vulnerability (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.005% (0.000050), reflecting very low probability of near-term exploitation. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The limited exploitation circumstances (resource exhaustion under specific conditions) further reduce practical exploitability (Android Security Bulletin).
Google addressed this vulnerability in the Android Security Bulletin dated December 1, 2025; devices receiving the 2025-12-01 security patch level or later are protected. Users and administrators should apply the latest Android security update immediately and ensure devices are running Android 13, 14, 15, or 16 with the December 2025 patch applied. As a supplementary measure, reviewing and restricting app permissions and monitoring for suspicious local app behaviors can reduce exposure until patching is complete (Android Security Bulletin, AOSP Patch).
Coverage of CVE-2025-48590 has been limited to routine security bulletin roundups. Security news outlets such as BeyondMachines and TheCyberThrone covered it as part of the broader Google December 2025 Android patch cycle, which addressed over 100 vulnerabilities. No notable individual researcher commentary or significant social media discussion specific to this CVE has been observed (Android Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."