CVE-2025-48590
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48590 is a local denial-of-service vulnerability in Android's AppOpsService.java that allows a malicious app to prevent users from dialing emergency services under limited circumstances via resource exhaustion. The flaw resides in the verifyAndGetBypass method and affects Android versions 13, 14, 15, and 16. No elevated privileges are required, and user interaction is not needed for exploitation. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).

Technical details

The root cause is uncontrolled resource consumption (CWE-400) within the verifyAndGetBypass method of AppOpsService.java in the Android framework. A low-privileged local app can trigger resource exhaustion through this method, which under certain conditions prevents the telephony stack from completing emergency call setup. The attack vector is local, requires only low privileges, and no user interaction, making it exploitable by any installed app without special permissions. The patch was committed to the Android Open Source Project (AOSP) frameworks/base repository (AOSP Patch, Android Security Bulletin).

Impact

Successful exploitation results in a local denial-of-service condition specifically targeting emergency call functionality, with high availability impact and no confidentiality or integrity impact. A malicious app installed on the device could, under limited circumstances, exhaust resources in the AppOps service and block the user from placing emergency calls (e.g., 911, 112), posing a direct risk to user safety. There is no evidence of lateral movement potential or data exposure associated with this vulnerability (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.005% (0.000050), reflecting very low probability of near-term exploitation. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The limited exploitation circumstances (resource exhaustion under specific conditions) further reduce practical exploitability (Android Security Bulletin).

Mitigation and workarounds

Google addressed this vulnerability in the Android Security Bulletin dated December 1, 2025; devices receiving the 2025-12-01 security patch level or later are protected. Users and administrators should apply the latest Android security update immediately and ensure devices are running Android 13, 14, 15, or 16 with the December 2025 patch applied. As a supplementary measure, reviewing and restricting app permissions and monitoring for suspicious local app behaviors can reduce exposure until patching is complete (Android Security Bulletin, AOSP Patch).

Community reactions

Coverage of CVE-2025-48590 has been limited to routine security bulletin roundups. Security news outlets such as BeyondMachines and TheCyberThrone covered it as part of the broader Google December 2025 Android patch cycle, which addressed over 100 vulnerabilities. No notable individual researcher commentary or significant social media discussion specific to this CVE has been observed (Android Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management