CVE-2025-48618
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48618 is a lockscreen bypass vulnerability in Android's processLaunchBrowser method within CommandParamsFactory.java, caused by improper locking (CWE-667). It allows an attacker with physical access to interact with the browser from the lockscreen, leading to physical escalation of privilege. Affected versions include Android 13, 14, 15, and 16. The vulnerability was disclosed via the Google Android Security Bulletin dated December 1, 2025, and published to NVD on December 8, 2025. It carries a CVSS v3.1 base score of 6.8 (Medium/High) with a physical attack vector (Android Security Bulletin).

Technical details

The root cause is improper locking (CWE-667) in the processLaunchBrowser method of CommandParamsFactory.java within Android's telephony framework. Due to insufficient synchronization or locking controls, an attacker with physical access to a locked device can trigger browser interactions that should be restricted by the lockscreen. No additional execution privileges are required, and no user interaction is needed for exploitation. A patch commit is available in the Android open-source project (Android AOSP Patch, Android Security Bulletin).

Impact

Successful exploitation allows a physically present attacker to bypass lockscreen restrictions and interact with the browser on the target device, potentially accessing sensitive browsing data, modifying browser settings, or leveraging browser functionality for further compromise. The vulnerability carries high confidentiality, integrity, and availability impacts per its CVSS scoring. Because exploitation requires physical access, the scope of impact is limited to the targeted device, with no direct path to network-based lateral movement (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000070, reflecting minimal automated exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for physical device access, significantly limiting the attacker pool (Android Security Bulletin).

Exploitation steps

  1. Physical Access: Obtain physical access to an Android device (version 13–16) that is in a locked state.
  2. Trigger Browser Launch: Interact with the device in a manner that invokes the processLaunchBrowser method in CommandParamsFactory.java — for example, via a crafted telephony command or interaction with a connected accessory that triggers the vulnerable code path.
  3. Bypass Lockscreen: Due to the improper locking mechanism, the browser launches or becomes interactive without requiring the user to authenticate, bypassing lockscreen restrictions.
  4. Access Sensitive Data: Use the unlocked browser session to access saved credentials, browsing history, open tabs, or web-based accounts, or to navigate to attacker-controlled pages for further exploitation (Android Security Bulletin).

Indicators of compromise

  • Logs: Unexpected browser launch events in Android system logs (logcat) while the device is in a locked state; entries from CommandParamsFactory or telephony framework indicating processLaunchBrowser was called without an authenticated session.
  • Process: Browser process (com.android.chrome or equivalent) appearing active in process lists while the device screen is locked.
  • Device Behavior: Browser application visible or active on the device without the user having unlocked the device; unexpected browser history entries or open tabs appearing after a period of unattended device access.

Mitigation and workarounds

Google released a patch as part of the Android Security Bulletin for December 1, 2025; the fix is available in the AOSP telephony framework (Android AOSP Patch). Users should apply the December 2025 Android security patch level immediately. As interim mitigations, organizations should enforce strong lockscreen mechanisms, restrict physical access to sensitive devices, and consider enhanced mobile device management (MDM) controls for high-security environments (Android Security Bulletin).

Community reactions

The vulnerability was covered in the context of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Samsung's December 2025 security patch also incorporated fixes for this and related issues. Coverage was largely routine, with security news outlets such as BeyondMachines and TheCyberThrone noting the bulletin's breadth. No notable individual researcher commentary or significant social media discussion specific to CVE-2025-48618 has been identified (Android Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management