2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48544HIGH7.8In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le...
CVE-2025-48543HIGH8.8In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft...
CVE-2025-48542MEDIUM5.5In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh...
CVE-2025-48541HIGH7.8In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope...
CVE-2025-48540HIGH7.8In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co...
CVE-2025-48539HIGH8In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t...
CVE-2025-48538MEDIUM5.5In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa...
CVE-2025-48537HIGH7.1In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This cou...
CVE-2025-48535HIGH7.8In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatc...
CVE-2025-48534HIGH8.8In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic err...
CVE-2025-48533HIGH7In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race ...
CVE-2025-48532HIGH7.3In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission du...
CVE-2025-48531HIGH7.8In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. T...
CVE-2025-48530HIGH8.1In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This...
CVE-2025-48529MEDIUM5.5In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused...
CVE-2025-48528MEDIUM4In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead...
CVE-2025-48527MEDIUM6.2In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the cod...
CVE-2025-48526MEDIUM4In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActi...
CVE-2025-48524MEDIUM5.5In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This c...
CVE-2025-48523HIGH7.8In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic err...
CVE-2025-48522HIGH7.8In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logi...
CVE-2025-32350HIGH7.8In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to...
CVE-2025-32349HIGH7.8In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to l...
CVE-2025-32347HIGH7.8In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an uns...
CVE-2025-32346HIGH7.8In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now