Security Advisory

CVE-2025-48545

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-09-04 18:34:24
Last updated 2026-03-04 14:23:54
Assigner google_android
State PUBLISHED

Description

In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.