
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48609 is a path traversal vulnerability in Android's MmsProvider.java that allows unauthenticated, network-based attackers to arbitrarily delete files affecting telephony, SMS, and MMS functionalities without requiring any privileges or user interaction. The vulnerability affects Google Android versions 14.0, 15.0, and 16.0. It was published on March 2, 2026, and addressed in the March 2026 Android Security Bulletin. It carries a CVSS v3.1 base score of 9.1 (Critical) (Android Security Bulletin, Red Hat Advisory).
The root cause is a path traversal error (related to CWE-400: Uncontrolled Resource Consumption) present in multiple functions within MmsProvider.java, a core Android component handling MMS content provider operations. By crafting malicious requests that exploit insufficient path validation, a remote unauthenticated attacker can cause the provider to delete arbitrary files outside the intended directory scope. No privileges are required and no user interaction is necessary, making the attack surface particularly broad. The vulnerability is accessible over the network with low attack complexity (Android Security Bulletin, Red Hat Advisory).
Successful exploitation results in arbitrary file deletion on the affected Android device, permanently disrupting telephony, SMS, and MMS functionalities — constituting a local denial of service with potentially irreversible effects on core communication services. The integrity and availability impacts are rated High, while there is no confidentiality impact. Because the attack requires no user interaction and no privileges, it can be triggered remotely against any vulnerable Android 14, 15, or 16 device, potentially rendering the device unable to send or receive calls and messages (Android Security Bulletin).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). No threat actor attribution has been reported. The EPSS score is approximately 0.012% (0.000120), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the combination of network accessibility, no required privileges, no user interaction, and low attack complexity makes it a candidate for future weaponization (Android Security Bulletin).
Google addressed this vulnerability in the March 2026 Android Security Bulletin (patch level 2026-03-01). Users and organizations should update all affected Android 14.0, 15.0, and 16.0 devices to the patched security patch level as soon as possible. Samsung has also incorporated this fix in its January 2026 security update rollout for Galaxy devices (Android Security Bulletin, Samsung Security). No configuration-based workarounds have been published; patching is the only recommended remediation.
The CIS issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for remote code execution and denial of service, referencing this bulletin (CIS Advisory). GBHackers reported on the broader March 2026 Android security update fixing 129 flaws, including this vulnerability (GBHackers). Social media coverage via The Hacker Wire on Mastodon and Bluesky noted the patch release. Huawei also acknowledged the vulnerability in its May 2026 security bulletin (Huawei Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."