Junglewise Threat Intelligence

CVE-2025-48648: Google Android denial of service in NotificationManagerService

CVE-2025-48648 · Severity: info · CVSS 5.5 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A vulnerability in the Android operating system's notification service could allow a malicious application to crash the system or make it unresponsive. This occurs through resource exhaustion, effectively preventing the device from functioning normally. The attack can be carried out by a local app without requiring any special permissions or user interaction.

Technical details

A denial of service vulnerability exists in the 'isSameApp' method of NotificationManagerService.java within the Android System component. The flaw is rooted in improper resource management that can be triggered to cause resource exhaustion. A local attacker can exploit this to cause a persistent denial of service (DoS) state on the device. The vulnerability does not require elevated privileges or user interaction to execute. Google addressed this in the June 2026 Android Security Bulletin for Android versions 14, 15, and 16.

Affected products

  • Google Android 14, 15, 16

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin
  • 2026-06-01: patched: Security patch levels of 2026-06-05 or later address this issue

References

Related threats