CVE-2025-48597
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48597 is a tapjacking/overlay attack vulnerability in the Android operating system that allows a low-privileged local attacker to trick users into accepting permissions without their knowledge, leading to local escalation of privilege. It affects Android versions 14.0, 15.0, and 16.0, and was disclosed as part of Google's December 2025 Android Security Bulletin published on December 1, 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), with no additional execution privileges required and no user interaction needed for exploitation (Android Bulletin).

Technical details

The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) and exists in multiple locations within the Android framework (specifically in platform/frameworks/base). An attacker exploits this by deploying a malicious overlay or transparent UI layer on top of a legitimate permission dialog, causing the user's tap to be registered as consent to a permission they did not intend to grant — a technique known as tapjacking. The attack requires only low-level local privileges and no user interaction beyond the incidental tap, making it particularly stealthy. The relevant source code fix is available in the Android open-source repository (Android Source Fix, Android Bulletin).

Impact

Successful exploitation can result in high impacts to confidentiality, integrity, and availability on the affected device. By silently granting elevated permissions to a malicious application, an attacker could gain unauthorized access to sensitive data (contacts, location, camera, microphone), modify system settings, or disrupt device functionality. The scope is limited to the compromised device, but the ability to silently escalate privileges could enable further malicious activity such as spyware installation or credential theft (Android Bulletin).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Android Bulletin). The EPSS score is extremely low at approximately 0.005%, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection is supported by Qualys scanner (detection ID 610747).

Exploitation steps

  1. Setup: The attacker installs a malicious application on the target Android device (versions 14, 15, or 16) that holds the SYSTEM_ALERT_WINDOW permission or uses another overlay-capable mechanism.
  2. Trigger permission dialog: The attacker's app waits for or triggers a scenario where the Android system displays a sensitive permission dialog (e.g., granting access to location, contacts, or microphone).
  3. Deploy overlay: The malicious app renders a transparent or visually deceptive UI layer (tapjacking overlay) precisely over the permission dialog's "Allow" button, potentially displaying a benign-looking UI element to the user.
  4. Capture user tap: When the user taps what they believe is an innocuous UI element, the tap is intercepted by the overlay and registered as acceptance of the underlying permission dialog.
  5. Privilege escalation: The malicious app now holds the granted permission, enabling it to access sensitive resources or perform privileged actions without the user's informed consent (Android Bulletin, Android Source Fix).

Indicators of compromise

  • Application Behavior: Applications requesting SYSTEM_ALERT_WINDOW or TYPE_APPLICATION_OVERLAY permissions that display overlays coinciding with system permission dialogs.
  • Logs: Android system logs (logcat) showing permission grants for sensitive permissions (e.g., READ_CONTACTS, ACCESS_FINE_LOCATION, RECORD_AUDIO) that the user did not consciously approve; look for PackageManager or PermissionController log entries with unexpected grants.
  • File System: Presence of newly installed APKs with overlay-capable permissions combined with unusual background activity.
  • Process: Unexpected foreground service or overlay window activity from third-party applications during system permission dialog display events.

Mitigation and workarounds

Google has released a patch as part of the December 2025 Android Security Bulletin (security patch level 2025-12-01). Users and administrators should update all affected Android 14, 15, and 16 devices to the December 2025 security patch level or later as the primary remediation. As a workaround, users should avoid installing applications from untrusted sources and review which applications hold the SYSTEM_ALERT_WINDOW (draw over other apps) permission, revoking it where unnecessary (Android Bulletin).

Community reactions

The vulnerability received routine coverage as part of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Security aggregators such as BeyondMachines and RedPacket Security flagged it in their patch summaries. No notable independent researcher commentary or significant social media discussion specific to this CVE has been observed beyond standard bulletin coverage (Android Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management