CVE-2025-48607
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48607 is a local denial-of-service vulnerability in Android 15.0 and 16.0 caused by a logic error that allows the creation of an excessive number of app operations ("app ops"). Disclosed in Google's December 2025 Android Security Bulletin (published December 1, 2025), the flaw requires only low-privilege local access and no user interaction to exploit. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Bulletin).

Technical details

The vulnerability (CWE classification consistent with logic errors leading to resource exhaustion) resides in multiple locations within the Android framework's app ops management code (frameworks/base). A logic error allows a low-privileged local attacker to repeatedly trigger the creation of app ops entries without proper bounds checking or rate limiting, eventually exhausting system resources. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction (UI:N). A patch commit is publicly available on the Android Open Source Project (AOSP) repository (AOSP Commit, Android Bulletin).

Impact

Successful exploitation leads to a local denial-of-service condition on affected Android devices, degrading or disrupting device functionality. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability (A:H). An attacker with a low-privilege local foothold (e.g., a malicious app) could render the device unresponsive or force a restart without any user interaction (Android Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000050 (approximately 0.005%), reflecting minimal likelihood of near-term exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Bulletin).

Mitigation and workarounds

Google released a patch for this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01), covering Android 15.0 and 16.0. The fix is available via the AOSP commit 03d7040699148c961df09dec301d8a1e982ee231. Users and administrators should apply the December 2025 security update to all affected Android devices as soon as it is available from their device manufacturer. As an interim measure, restricting installation of untrusted or unknown applications reduces the local attack surface (Android Bulletin, AOSP Commit).

Community reactions

Coverage of CVE-2025-48607 has been limited to routine security bulletin aggregation. Samsung's security update for October 2025 was noted in community coverage, and the December 2025 Android bulletin — which includes this CVE — was covered by outlets such as BeyondMachines and Rapid Meta as part of broader reporting on Google's patch of over 100 Android vulnerabilities that month (Android Bulletin). No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management