VDB
CISA-2025-48645
CISA-2025-48645
PUBLISHED
CVSS 9.8 CRITICAL
Reported by google_android · Published March 2, 2026
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | 16-qpr2, 16, 15 | |
| Android | 16-qpr2, 16, 15 |
Timeline
- Mar 2, 2026 CVE Published
- Mar 6, 2026 CVE Updated