CVE-2025-48609
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48609 is a path traversal vulnerability in Android's MmsProvider.java that allows unauthenticated, network-based attackers to arbitrarily delete files affecting telephony, SMS, and MMS functionalities without requiring any privileges or user interaction. The vulnerability affects Google Android versions 14.0, 15.0, and 16.0. It was published on March 2, 2026, and addressed in the March 2026 Android Security Bulletin. It carries a CVSS v3.1 base score of 9.1 (Critical) (Android Security Bulletin, Red Hat Advisory).

Technical details

The root cause is a path traversal error (related to CWE-400: Uncontrolled Resource Consumption) present in multiple functions within MmsProvider.java, a core Android component handling MMS content provider operations. By crafting malicious requests that exploit insufficient path validation, a remote unauthenticated attacker can cause the provider to delete arbitrary files outside the intended directory scope. No privileges are required and no user interaction is necessary, making the attack surface particularly broad. The vulnerability is accessible over the network with low attack complexity (Android Security Bulletin, Red Hat Advisory).

Impact

Successful exploitation results in arbitrary file deletion on the affected Android device, permanently disrupting telephony, SMS, and MMS functionalities — constituting a local denial of service with potentially irreversible effects on core communication services. The integrity and availability impacts are rated High, while there is no confidentiality impact. Because the attack requires no user interaction and no privileges, it can be triggered remotely against any vulnerable Android 14, 15, or 16 device, potentially rendering the device unable to send or receive calls and messages (Android Security Bulletin).

Exploitability

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). No threat actor attribution has been reported. The EPSS score is approximately 0.012% (0.000120), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the combination of network accessibility, no required privileges, no user interaction, and low attack complexity makes it a candidate for future weaponization (Android Security Bulletin).

Mitigation and workarounds

Google addressed this vulnerability in the March 2026 Android Security Bulletin (patch level 2026-03-01). Users and organizations should update all affected Android 14.0, 15.0, and 16.0 devices to the patched security patch level as soon as possible. Samsung has also incorporated this fix in its January 2026 security update rollout for Galaxy devices (Android Security Bulletin, Samsung Security). No configuration-based workarounds have been published; patching is the only recommended remediation.

Community reactions

The CIS issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for remote code execution and denial of service, referencing this bulletin (CIS Advisory). GBHackers reported on the broader March 2026 Android security update fixing 129 flaws, including this vulnerability (GBHackers). Social media coverage via The Hacker Wire on Mastodon and Bluesky noted the patch release. Huawei also acknowledged the vulnerability in its May 2026 security bulletin (Huawei Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management