CVE-2025-48536

7.8HIGH

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalati

公開日: 12/8/2025更新日: 12/9/2025

説明

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

AI分析AIによる分析

影響を受ける製品

googleandroid
13.0
googleandroid
14.0
googleandroid
15.0
googleandroid
16.0

参照