
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48646 is a confused deputy vulnerability in Android's ActivityStarter.java (executeRequest method) that allows a local attacker to bypass activity launch restrictions and escalate privileges. It affects Android versions 14.0, 15.0, and 16.0 (including QPR2 beta variants). The vulnerability was published on March 2, 2026, and patched via the Android Security Bulletin 2026-03-01. It carries a CVSS v3.1 base score of 7.8 (High), requiring no additional execution privileges but needing user interaction (Android Security Bulletin, Red Hat CVE).
The root cause is classified as CWE-441 (Unintended Proxy or Intermediary — 'Confused Deputy'), located in the executeRequest method of ActivityStarter.java within the Android framework. The flaw allows a less-privileged component to exploit the elevated trust of the Activity Manager to launch arbitrary activities that would otherwise be restricted, effectively bypassing Android's activity launch controls. Exploitation is local and requires user interaction, but no additional execution privileges are needed beyond those of a standard unprivileged app (Android Security Bulletin, Red Hat CVE).
Successful exploitation leads to local escalation of privilege, with high impact on confidentiality, integrity, and availability. An attacker can launch arbitrary activities — including those belonging to privileged system applications — potentially accessing sensitive user data, modifying system state, or disrupting application availability. The scope is limited to the compromised device, but the ability to launch privileged activities could facilitate further exploitation of the local system (Android Security Bulletin).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (Red Hat CVE). The EPSS score is extremely low at 0.000060, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and user interaction, which limits the attack surface compared to remote or zero-click vulnerabilities.
executeRequest method in ActivityStarter.java, exploiting the confused deputy flaw to have the privileged Activity Manager launch an arbitrary restricted activity on its behalf.Google has released a patch addressing this vulnerability in the Android Security Bulletin dated 2026-03-01; devices should be updated to a security patch level of 2026-03-01 or later. Affected versions include Android 14.0, 15.0, and 16.0 (including QPR2 beta variants). Users and administrators should apply available OEM security updates promptly; Samsung and other OEMs have incorporated this fix in their February/March 2026 update cycles. No configuration-based workaround is publicly documented — patching is the recommended remediation (Android Security Bulletin, Red Hat CVE).
The CIS issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for remote code execution and privilege escalation, including CVE-2025-48646 (CIS Advisory). Samsung incorporated the fix in its February 2026 security update cycle. GrapheneOS also addressed this CVE in its releases. Community and media reaction has been limited given the absence of public exploits or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."