
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48645 is a local privilege escalation vulnerability in Android's DeviceAdminInfo.java, specifically within the loadDescription method. Improper input validation in this component allows a persistent package to be established, enabling a low-privileged local attacker to escalate privileges without any user interaction. Affected versions include Android 14.0, 15.0, and 16.0 (including QPR2 beta variants). The vulnerability was published on March 2, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-269 (Improper Privilege Management), stemming from insufficient input validation in the loadDescription function of DeviceAdminInfo.java, a component responsible for handling Device Administrator metadata on Android. An attacker with a low-privileged local account can craft a malicious package that exploits this flaw to persist on the device and gain elevated system permissions. No additional execution privileges are required, and the attack vector is local with low complexity, making it straightforward to exploit once an attacker has initial access to the device (Android Security Bulletin).
Successful exploitation grants a local attacker high confidentiality, integrity, and availability impact — effectively full control over the affected Android device. The attacker can persist a malicious package with elevated privileges, potentially enabling access to sensitive user data, modification of system settings, and disruption of device availability. The scope is limited to the compromised device, but elevated privileges could facilitate further abuse of device administrator capabilities (Android Security Bulletin, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. A vendor patch is available via the Google Android March 2026 security bulletin (Android Security Bulletin).
Google has released a patch addressing CVE-2025-48645 in the Android Security Bulletin for 2026-03-01, covering Android versions 14.0, 15.0, and 16.0. Users and administrators should apply the March 2026 Android security update (patch level 2026-03-01 or later) as soon as it is available for their device. OEM-specific updates (e.g., Samsung, Huawei) incorporating this patch should also be applied promptly. No configuration-based workarounds have been published (Android Security Bulletin, CIS Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in the March 2026 Android update, including CVE-2025-48645, flagging the potential for privilege escalation (CIS Advisory). Red Hat also tracked the CVE, though Android is not a Red Hat product, reflecting broad industry monitoring of the issue (Red Hat CVE). No significant independent researcher commentary or social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."