CVE-2025-48646
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48646 is a confused deputy vulnerability in Android's ActivityStarter.java (executeRequest method) that allows a local attacker to bypass activity launch restrictions and escalate privileges. It affects Android versions 14.0, 15.0, and 16.0 (including QPR2 beta variants). The vulnerability was published on March 2, 2026, and patched via the Android Security Bulletin 2026-03-01. It carries a CVSS v3.1 base score of 7.8 (High), requiring no additional execution privileges but needing user interaction (Android Security Bulletin, Red Hat CVE).

Technical details

The root cause is classified as CWE-441 (Unintended Proxy or Intermediary — 'Confused Deputy'), located in the executeRequest method of ActivityStarter.java within the Android framework. The flaw allows a less-privileged component to exploit the elevated trust of the Activity Manager to launch arbitrary activities that would otherwise be restricted, effectively bypassing Android's activity launch controls. Exploitation is local and requires user interaction, but no additional execution privileges are needed beyond those of a standard unprivileged app (Android Security Bulletin, Red Hat CVE).

Impact

Successful exploitation leads to local escalation of privilege, with high impact on confidentiality, integrity, and availability. An attacker can launch arbitrary activities — including those belonging to privileged system applications — potentially accessing sensitive user data, modifying system state, or disrupting application availability. The scope is limited to the compromised device, but the ability to launch privileged activities could facilitate further exploitation of the local system (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (Red Hat CVE). The EPSS score is extremely low at 0.000060, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and user interaction, which limits the attack surface compared to remote or zero-click vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify a target Android device running version 14.0, 15.0, or 16.0 that has not applied the 2026-03-01 security patch level.
  2. Malicious App Delivery: Deliver a malicious application to the target device (e.g., via sideloading or a third-party app store) that does not hold the necessary permissions to launch restricted activities directly.
  3. Trigger User Interaction: Induce the victim to interact with the malicious app (e.g., tap a button or open a link), satisfying the user interaction requirement for exploitation.
  4. Confused Deputy Abuse: The malicious app crafts an intent and routes it through the executeRequest method in ActivityStarter.java, exploiting the confused deputy flaw to have the privileged Activity Manager launch an arbitrary restricted activity on its behalf.
  5. Privilege Escalation: The attacker's app gains the ability to launch activities belonging to privileged system components, potentially accessing protected data or functionality not normally accessible to unprivileged apps (Android Security Bulletin).

Mitigation and workarounds

Google has released a patch addressing this vulnerability in the Android Security Bulletin dated 2026-03-01; devices should be updated to a security patch level of 2026-03-01 or later. Affected versions include Android 14.0, 15.0, and 16.0 (including QPR2 beta variants). Users and administrators should apply available OEM security updates promptly; Samsung and other OEMs have incorporated this fix in their February/March 2026 update cycles. No configuration-based workaround is publicly documented — patching is the recommended remediation (Android Security Bulletin, Red Hat CVE).

Community reactions

The CIS issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for remote code execution and privilege escalation, including CVE-2025-48646 (CIS Advisory). Samsung incorporated the fix in its February 2026 security update cycle. GrapheneOS also addressed this CVE in its releases. Community and media reaction has been limited given the absence of public exploits or active exploitation.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-15-binutils-devel
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management