
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48607 is a local denial-of-service vulnerability in Android 15.0 and 16.0 caused by a logic error that allows the creation of an excessive number of app operations ("app ops"). Disclosed in Google's December 2025 Android Security Bulletin (published December 1, 2025), the flaw requires only low-privilege local access and no user interaction to exploit. It carries a CVSS v3.1 base score of 5.5 (Medium) (Android Bulletin).
The vulnerability (CWE classification consistent with logic errors leading to resource exhaustion) resides in multiple locations within the Android framework's app ops management code (frameworks/base). A logic error allows a low-privileged local attacker to repeatedly trigger the creation of app ops entries without proper bounds checking or rate limiting, eventually exhausting system resources. The attack vector is local (AV:L), requires low privileges (PR:L), and no user interaction (UI:N). A patch commit is publicly available on the Android Open Source Project (AOSP) repository (AOSP Commit, Android Bulletin).
Successful exploitation leads to a local denial-of-service condition on affected Android devices, degrading or disrupting device functionality. There is no confidentiality or integrity impact — the vulnerability exclusively affects availability (A:H). An attacker with a low-privilege local foothold (e.g., a malicious app) could render the device unresponsive or force a restart without any user interaction (Android Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000050 (approximately 0.005%), reflecting minimal likelihood of near-term exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Android Bulletin).
Google released a patch for this vulnerability in the December 2025 Android Security Bulletin (patch level 2025-12-01), covering Android 15.0 and 16.0. The fix is available via the AOSP commit 03d7040699148c961df09dec301d8a1e982ee231. Users and administrators should apply the December 2025 security update to all affected Android devices as soon as it is available from their device manufacturer. As an interim measure, restricting installation of untrusted or unknown applications reduces the local attack surface (Android Bulletin, AOSP Commit).
Coverage of CVE-2025-48607 has been limited to routine security bulletin aggregation. Samsung's security update for October 2025 was noted in community coverage, and the December 2025 Android bulletin — which includes this CVE — was covered by outlets such as BeyondMachines and Rapid Meta as part of broader reporting on Google's patch of over 100 Android vulnerabilities that month (Android Bulletin). No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."