Junglewise Threat Intelligence

CVE-2025-48633: Google Android privilege escalation in DevicePolicyManagerService

CVE-2025-48633 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2025-12-02

Technologies: Android Framework, Google Android. Vendors: Android, Google.

Executive brief

A vulnerability in the Android operating system allows an attacker to gain unauthorized control over a device by exploiting a logic error in the device management service. This could allow a malicious app to elevate its privileges and access sensitive information without any interaction from the user. This flaw is known to be actively exploited in the wild, posing a significant risk to unpatched mobile devices.

Technical details

A logic error exists within the 'hasAccountsOnAnyUser' method of 'DevicePolicyManagerService.java' in the Android Framework. This flaw allows an attacker to add a Device Owner after the initial provisioning process has completed. Exploitation requires local access but no additional execution privileges or user interaction. Successful exploitation leads to local escalation of privilege (EoP) and unauthorized information disclosure. Google has released patches for Android versions 13 through 16, and the vulnerability is confirmed to be exploited in the wild.

Affected products

  • Google Android 13.0, 14.0, 15.0, 16.0

Timeline

  • 2025-12-01: advisory: Vendor advisory published by Google
  • 2025-12-02: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-12-08: disclosed: NVD publication date

Related threats