
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48618 is a lockscreen bypass vulnerability in Android's processLaunchBrowser method within CommandParamsFactory.java, caused by improper locking (CWE-667). It allows an attacker with physical access to interact with the browser from the lockscreen, leading to physical escalation of privilege. Affected versions include Android 13, 14, 15, and 16. The vulnerability was disclosed via the Google Android Security Bulletin dated December 1, 2025, and published to NVD on December 8, 2025. It carries a CVSS v3.1 base score of 6.8 (Medium/High) with a physical attack vector (Android Security Bulletin).
The root cause is improper locking (CWE-667) in the processLaunchBrowser method of CommandParamsFactory.java within Android's telephony framework. Due to insufficient synchronization or locking controls, an attacker with physical access to a locked device can trigger browser interactions that should be restricted by the lockscreen. No additional execution privileges are required, and no user interaction is needed for exploitation. A patch commit is available in the Android open-source project (Android AOSP Patch, Android Security Bulletin).
Successful exploitation allows a physically present attacker to bypass lockscreen restrictions and interact with the browser on the target device, potentially accessing sensitive browsing data, modifying browser settings, or leveraging browser functionality for further compromise. The vulnerability carries high confidentiality, integrity, and availability impacts per its CVSS scoring. Because exploitation requires physical access, the scope of impact is limited to the targeted device, with no direct path to network-based lateral movement (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at 0.000070, reflecting minimal automated exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for physical device access, significantly limiting the attacker pool (Android Security Bulletin).
processLaunchBrowser method in CommandParamsFactory.java — for example, via a crafted telephony command or interaction with a connected accessory that triggers the vulnerable code path.logcat) while the device is in a locked state; entries from CommandParamsFactory or telephony framework indicating processLaunchBrowser was called without an authenticated session.com.android.chrome or equivalent) appearing active in process lists while the device screen is locked.Google released a patch as part of the Android Security Bulletin for December 1, 2025; the fix is available in the AOSP telephony framework (Android AOSP Patch). Users should apply the December 2025 Android security patch level immediately. As interim mitigations, organizations should enforce strong lockscreen mechanisms, restrict physical access to sensitive devices, and consider enhanced mobile device management (MDM) controls for high-security environments (Android Security Bulletin).
The vulnerability was covered in the context of Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Samsung's December 2025 security patch also incorporated fixes for this and related issues. Coverage was largely routine, with security news outlets such as BeyondMachines and TheCyberThrone noting the bulletin's breadth. No notable individual researcher commentary or significant social media discussion specific to CVE-2025-48618 has been identified (Android Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."