
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48597 is a tapjacking/overlay attack vulnerability in the Android operating system that allows a low-privileged local attacker to trick users into accepting permissions without their knowledge, leading to local escalation of privilege. It affects Android versions 14.0, 15.0, and 16.0, and was disclosed as part of Google's December 2025 Android Security Bulletin published on December 1, 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), with no additional execution privileges required and no user interaction needed for exploitation (Android Bulletin).
The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) and exists in multiple locations within the Android framework (specifically in platform/frameworks/base). An attacker exploits this by deploying a malicious overlay or transparent UI layer on top of a legitimate permission dialog, causing the user's tap to be registered as consent to a permission they did not intend to grant — a technique known as tapjacking. The attack requires only low-level local privileges and no user interaction beyond the incidental tap, making it particularly stealthy. The relevant source code fix is available in the Android open-source repository (Android Source Fix, Android Bulletin).
Successful exploitation can result in high impacts to confidentiality, integrity, and availability on the affected device. By silently granting elevated permissions to a malicious application, an attacker could gain unauthorized access to sensitive data (contacts, location, camera, microphone), modify system settings, or disrupt device functionality. The scope is limited to the compromised device, but the ability to silently escalate privileges could enable further malicious activity such as spyware installation or credential theft (Android Bulletin).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Android Bulletin). The EPSS score is extremely low at approximately 0.005%, reflecting the current absence of observed exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection is supported by Qualys scanner (detection ID 610747).
SYSTEM_ALERT_WINDOW permission or uses another overlay-capable mechanism.SYSTEM_ALERT_WINDOW or TYPE_APPLICATION_OVERLAY permissions that display overlays coinciding with system permission dialogs.logcat) showing permission grants for sensitive permissions (e.g., READ_CONTACTS, ACCESS_FINE_LOCATION, RECORD_AUDIO) that the user did not consciously approve; look for PackageManager or PermissionController log entries with unexpected grants.Google has released a patch as part of the December 2025 Android Security Bulletin (security patch level 2025-12-01). Users and administrators should update all affected Android 14, 15, and 16 devices to the December 2025 security patch level or later as the primary remediation. As a workaround, users should avoid installing applications from untrusted sources and review which applications hold the SYSTEM_ALERT_WINDOW (draw over other apps) permission, revoking it where unnecessary (Android Bulletin).
The vulnerability received routine coverage as part of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Security aggregators such as BeyondMachines and RedPacket Security flagged it in their patch summaries. No notable independent researcher commentary or significant social media discussion specific to this CVE has been observed beyond standard bulletin coverage (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."