Junglewise Threat Intelligence

CVE-2025-48566: Android Framework permission bypass via confused deputy

CVE-2025-48566 · Severity: high · CVSS 7.8 · Published 2025-12-08

Technologies: Google Android. Vendors: Google.

Executive brief

Android's Framework component contains a permission bypass vulnerability due to confused deputy logic in multiple locations. An unprivileged app can exploit this to escalate its privileges locally without requiring additional system permissions or user interaction, potentially gaining access to sensitive device functionality and user data.

Technical details

This is a privilege escalation (EoP) vulnerability in the Android Framework caused by improper permission checks—specifically a confused deputy condition where a privileged component is tricked into performing actions on behalf of an unprivileged caller. The vulnerability exists in multiple Framework locations and allows local escalation of privilege with no additional execution privileges required and no user interaction needed for exploitation. Attack vector is local, with a malicious app able to exploit the permission bypass. Patches are available in Android versions 14, 15, 16, 16-qpr2, and 17 per the September 2026 security bulletin (2026-09-05 security patch level).

Affected products

  • Google Android 14, 15, 16, 16-qpr2, 17

Timeline

  • 2026-09-08: disclosed: Published in Android Security Bulletin September 2026
  • 2026-09-05: patched: Security patch level 2026-09-05 or later addresses the issue

References

Related threats