Junglewise Threat Intelligence

CVE-2025-48643: Google Android 17 privilege escalation in System component

CVE-2025-48643 · Severity: high · CVSS 7.8 · Published 2026-06-17

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system could allow a malicious application installed on a device to bypass security restrictions. This flaw enables an attacker to gain elevated system privileges without any interaction from the user. Successful exploitation could lead to full control over the device, potentially compromising sensitive user data and system integrity.

Technical details

A local escalation of privilege (EoP) vulnerability exists in the System component of Android 17. The flaw is rooted in improper input validation (CWE-20) across multiple locations, which allows for a provisioning bypass. A local attacker with low privileges can exploit this vulnerability to gain elevated permissions without requiring additional execution privileges or user interaction. The vulnerability was addressed in the Android 17 security release with a default security patch level of 2026-07-01.

Affected products

  • Google Android 17

Timeline

  • 2026-06-16: advisory: Initial release of Android 17 Security Release Notes
  • 2026-06-17: disclosed: NVD publication date

References

Related threats