Critical Severity Vulnerability
This vulnerability has been rated as Critical severity. Immediate action is recommended.
CVE-2025-48611
CriticalVulnerability Description
In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Severity Details
Weakness Type (CWE)
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- Description
- The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Base
Key Information
- Published Date
- March 10, 2026
