2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48544 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le... |
| CVE-2025-48543 | HIGH | 8.8 | 0.5% | Sep 4, 2025 | In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft... |
| CVE-2025-48542 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh... |
| CVE-2025-48541 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope... |
| CVE-2025-48540 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co... |
| CVE-2025-48539 | HIGH | 8 | 0.2% | Sep 4, 2025 | In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t... |
| CVE-2025-48538 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa... |
| CVE-2025-48537 | HIGH | 7.1 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou... |
| CVE-2025-48535 | HIGH | 7.8 | 0.2% | Sep 4, 2025 | In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatc... |
| CVE-2025-48534 | HIGH | 8.8 | 0.3% | Sep 4, 2025 | In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic err... |
| CVE-2025-48533 | HIGH | 7 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race ... |
| CVE-2025-48532 | HIGH | 7.3 | 0.1% | Sep 4, 2025 | In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission du... |
| CVE-2025-48531 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T... |
| CVE-2025-48530 | HIGH | 8.1 | 0.5% | Sep 4, 2025 | In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This... |
| CVE-2025-48529 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused... |
| CVE-2025-48528 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead... |
| CVE-2025-48527 | MEDIUM | 6.2 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the cod... |
| CVE-2025-48526 | MEDIUM | 4 | 0.1% | Sep 4, 2025 | In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActi... |
| CVE-2025-48524 | MEDIUM | 5.5 | 0.1% | Sep 4, 2025 | In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This c... |
| CVE-2025-48523 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err... |
| CVE-2025-48522 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi... |
| CVE-2025-32350 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to... |
| CVE-2025-32349 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l... |
| CVE-2025-32347 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns... |
| CVE-2025-32346 | HIGH | 7.8 | 0.1% | Sep 4, 2025 | In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now