Junglewise Threat Intelligence

CVE-2025-48600: Google Android information disclosure in IntentResolver

CVE-2025-48600 · Severity: medium · CVSS 5.5 · Published 2025-12-08

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability in the Android operating system could allow a malicious application installed on a device to access information belonging to other users. This occurs because the system fails to properly check permissions in certain files. An attacker could use this to bypass privacy boundaries and view sensitive data without any interaction from the device owner.

Technical details

A missing authorization (CWE-862) vulnerability exists in multiple files within the Android System component, specifically related to the IntentResolver module. A local attacker with low privileges can exploit this flaw to reveal sensitive information across different user profiles on the same device. The vulnerability does not require user interaction or additional execution privileges. The issue has been addressed in the June 2026 Android Security Bulletin with patches available for Android versions 14, 15, and 16.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2025-12-08: disclosed: Initial NVD publication date
  • 2026-06-01: patched: Security patch released in Android June 2026 Bulletin

References

Related threats