Junglewise Threat Intelligence

CVE-2025-48649: Google Android Framework permissions bypass in multiple locations

CVE-2025-48649 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A vulnerability in the Android operating system could allow a malicious application to bypass security permissions. This flaw enables the resetting of user-selected permission settings, potentially allowing an app to gain higher levels of access to device data or functions than intended. This occurs without requiring any interaction from the user.

Technical details

A permissions bypass vulnerability exists in multiple locations within the Android Framework component. The flaw allows for the resetting of user-selected permission selections, which can be leveraged to achieve local escalation of privilege (EoP). Exploitation does not require additional execution privileges or user interaction. The vulnerability affects Android versions 14, 15, 16, and 16-qpr2. A fix is available as part of the June 2026 Android Security Bulletin (patch level 2026-06-05).

Affected products

  • Google Android Framework 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in Android Security Bulletin June 2026
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats