
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48639 is a tapjacking/overlay vulnerability in Android's DefaultTransitionHandler.java that allows a malicious app to trick users into unknowingly granting permissions, leading to local escalation of privilege. It affects Android versions 13, 14, 15, and 16. The vulnerability was disclosed as part of Google's December 2025 Android Security Bulletin, published on December 1, 2025. It carries a CVSS v3.1 base score of 7.3 (High) (Android Bulletin).
The root cause is classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), a class of vulnerability commonly known as tapjacking or clickjacking on Android. An attacker deploys a malicious overlay or transparent UI layer on top of a legitimate permission dialog rendered by DefaultTransitionHandler.java, causing the user's tap to be registered as consent for a permission grant they did not intend to approve. Exploitation requires the attacker to have a locally installed app with overlay drawing capability, and user interaction (a tap) is required — no additional execution privileges are needed (Android Bulletin). Patch commits are available in the Android Open Source Project for both frameworks/native and frameworks/base (EUVD).
Successful exploitation allows a low-privileged local application to silently obtain elevated permissions on the device without the user's informed consent, impacting confidentiality, integrity, and availability (all rated High in the CVSS scoring). Depending on the permissions obtained, an attacker could access sensitive user data (contacts, location, camera, microphone), modify device settings, or install additional malicious components. The attack is constrained to the local device and does not directly enable remote code execution or lateral movement across a network (Android Bulletin).
There is no public evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2025-48639 as of the time of this report. The EPSS score is extremely low at approximately 0.008%, reflecting a low near-term exploitation probability. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a locally installed malicious app and user interaction, which limits the attack surface compared to remote vulnerabilities (Android Bulletin).
SYSTEM_ALERT_WINDOW (draw over other apps) permission or leverages another overlay mechanism available to low-privileged apps.DefaultTransitionHandler.java during app transitions or permission request flows.SYSTEM_ALERT_WINDOW or overlay permissions without a clear legitimate use case; apps that display transparent or near-invisible windows over system dialogs.logcat) showing unexpected permission grants for sensitive permissions (e.g., camera, microphone, location, contacts) to apps that were not explicitly authorized by the user.Google released patches for CVE-2025-48639 in the December 2025 Android Security Bulletin (patch level 2025-12-01). Users and administrators should apply the December 2025 security update to all affected Android 13, 14, 15, and 16 devices as soon as it is available from their device manufacturer. As a workaround, users should avoid installing apps from untrusted sources and review app permissions regularly via Android's Privacy Dashboard. OEM vendors including Samsung and Huawei have incorporated these patches into their respective December 2025 and April 2026 security updates (Android Bulletin, Samsung).
The vulnerability was covered as part of broader reporting on Google's December 2025 Android Security Bulletin, which addressed over 100 vulnerabilities. Coverage from outlets such as BeyondMachines and SammyFans noted the scale of the patch release but did not single out CVE-2025-48639 for specific commentary. No notable individual researcher analysis or significant social media discussion specific to this CVE has been identified (BeyondMachines, Samsung).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."