Cyber Resilience

CVE-2025-48633

Google Android 13.0 … 16.0

CISA KEVActive ExploitationEUVD Exploited
Published
08 December 2025
Modified
10 December 2025
KEV Added
02 December 2025
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0026 17th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2025-48633 is a medium-severity an unspecified weakness vulnerability in Google Android. Its CVSS base score is 5.5 (Medium).

Operationally, ranked at the 17th percentile by exploit likelihood (below the median); CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2025-48633 is a logic error in the hasAccountsOnAnyUser function of DevicePolicyManagerService.java within the Android Open Source Project's platform/frameworks/base component. This flaw enables the addition of a Device Owner after device provisioning, resulting in a local escalation of privilege. Exploitation requires no additional execution privileges or user interaction. The vulnerability carries a CVSS v3.1 base score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) and is associated with CWE information not yet detailed by NVD.

A local attacker with low privileges (PR:L) on an affected Android device can exploit this issue without additional attack complexity or user involvement. Successful exploitation allows the attacker to elevate privileges by installing a Device Owner, granting high confidentiality access (C:H) as reflected in the CVSS metrics, though without integrity or availability impact.

The Android Security Bulletin for December 2025-12-01 addresses this vulnerability and provides patch details. A specific code change fixing the issue is available in the commit at https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93. Mitigation involves applying the relevant Android updates, and the vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog at https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48633, indicating real-world exploitation.

EU & UK References

Vulnerability Data

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

more

is not needed for exploitation.

CWE(s)
KEV Date Added
02 December 2025

Related Threats

CVEs Like This One

CVE-2025-48543Same product: Google Androidboth on KEV
CVE-2024-29745Same product: Google Androidboth on KEV
CVE-2020-0041Same product: Google Androidboth on KEV
CVE-2024-32896Same product: Google Androidboth on KEV
CVE-2024-43093Same product: Google Androidboth on KEV
CVE-2023-20963Same product: Google Androidboth on KEV
CVE-2025-48572Same product: Google Androidboth on KEV
CVE-2025-48595Same product: Google Androidboth on KEV
CVE-2021-39793Same product: Google Androidboth on KEV
CVE-2021-1048Same product: Google Androidboth on KEV

Affected Assets

google
android
13.0, 14.0, 15.0, 16.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References