CVE-2025-48591
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48591 is a missing permission check vulnerability in Android that allows a local attacker to read files belonging to another user, resulting in local information disclosure. It affects Android versions 13.0, 14.0, and 15.0, with the flaw present in multiple locations including the frameworks/base and packages/services/Mms components. The vulnerability was disclosed on December 8, 2025, with a patch made available in the December 2025 Android Security Bulletin. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Security Bulletin).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): in multiple code locations within Android's framework and MMS service, file access operations lack the necessary permission checks to enforce user isolation. An attacker with a low-privileged local account can exploit this without any user interaction or elevated privileges, simply by invoking the affected APIs or accessing the relevant file paths. Patches were committed to android.googlesource.com/platform/frameworks/base and android.googlesource.com/platform/packages/services/Mms (Android Security Bulletin).

Impact

Successful exploitation leads to local information disclosure, allowing a low-privileged user or application to read files owned by other users on the same device. This could expose sensitive personal data, messages (including MMS content), or application files belonging to other accounts. There is no impact on integrity or availability, and the scope is limited to the affected device (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The vulnerability requires only a low-privileged local account and no user interaction, lowering the barrier for exploitation if access to the device is obtained. The EPSS score is approximately 0.006%, reflecting a low probability of near-term exploitation. CVE-2025-48591 is not listed in the CISA Known Exploited Vulnerabilities catalog (Android Security Bulletin).

Mitigation and workarounds

Google has addressed this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the December 2025 Android security update to all affected devices running Android 13, 14, or 15. No configuration-based workaround has been published; updating to the patched security patch level is the recommended remediation (Android Security Bulletin).

Community reactions

The vulnerability was noted in routine coverage of the December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Security news outlets such as BeyondMachines and TheCyberThrone covered the bulletin broadly, and Samsung's October 2025 update was also noted as addressing related Android issues. No significant independent researcher commentary or social media discussion specific to CVE-2025-48591 has been observed (Android Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management