Junglewise Threat Intelligence

CVE-2025-48652: Google Android Framework MDM policy bypass in InstallRepository.kt

CVE-2025-48652 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android Framework. Vendors: Google.

Executive brief

A logic error in the Android Framework allows for the bypass of Mobile Device Management (MDM) policies. This could allow a local user or malicious application to gain elevated privileges and circumvent corporate security restrictions without any user interaction. Such a bypass undermines the security controls used by organizations to manage and secure mobile devices.

Technical details

A logic error exists within the 'performPreInstallChecks' function of 'InstallRepository.kt' in the Android Framework. This vulnerability allows an attacker to bypass Mobile Device Management (MDM) policies, leading to local escalation of privilege (EoP). The exploit requires no additional execution privileges and no user interaction. The issue affects Android versions 15, 16, and 16-qpr2. Google has addressed this vulnerability in the June 2026 Android Security Bulletin with security patch level 2026-06-05 or later.

Affected products

  • Google Android Framework 15, 16, 16-qpr2

Timeline

  • 2026-06-01: advisory: Published in the June 2026 Android Security Bulletin
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue

References

Related threats