CVE-2025-48650
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-48650 is a SQL injection vulnerability affecting Google Android versions 14, 15, and 16 that can lead to local privilege escalation and information disclosure. The flaw exists in multiple locations within the Android OS and requires no additional execution privileges or user interaction to exploit. It was published on March 2, 2026, as part of Google's March 2026 Android Security Bulletin. The vulnerability carries a CVSS v3.1 base score of 8.4 (High) (Android Security Bulletin, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), indicating that user-supplied input is not properly sanitized before being incorporated into SQL queries at multiple code locations within Android. The attack vector is local, meaning an attacker with local access to the device can trigger the SQL injection without requiring elevated privileges or any user interaction. Exploitation can result in both information disclosure (reading sensitive data from internal databases) and local privilege escalation. No specific technical write-ups or public proof-of-concept code have been identified at this time (Android Security Bulletin, Red Hat CVE).

Impact

Successful exploitation of CVE-2025-48650 allows a local attacker to disclose sensitive information stored in Android's internal databases and escalate privileges on the affected device, with high impact to confidentiality, integrity, and availability. Because no user interaction or special permissions are required, a malicious application or a local attacker with shell access could directly trigger the vulnerability to gain elevated permissions. The scope is limited to the affected device (unchanged scope), but privilege escalation could enable further compromise of device data and functionality (Android Security Bulletin).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation reported for CVE-2025-48650 as of the time of this report. The EPSS score is approximately 0.007% (0.000070), indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Red Hat CVE, Android Security Bulletin).

Mitigation and workarounds

Google addressed CVE-2025-48650 in the March 2026 Android Security Bulletin (patch level 2026-03-01). Users and administrators should apply the March 2026 security update to all affected Android 14, 15, and 16 devices as soon as it is available from their device manufacturer or carrier. In the interim, restricting installation of untrusted applications and limiting local shell access can reduce the attack surface. Huawei has also referenced this CVE in its May 2026 security bulletin for affected devices (Android Security Bulletin, Huawei Bulletin, CIS Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Google Android OS that could allow for remote code execution and privilege escalation, including CVE-2025-48650, recommending prompt patching (CIS Advisory). Samsung device coverage was noted in early February 2026 security update reporting (SammyFans). No significant independent researcher commentary or social media discussion has been identified for this specific CVE.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management