-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
CVE-2025-48580 - High Severity Vulnerability
Vulnerable Library - CertInstallerandroid-10.0.0_r15
Library home page: https://android.googlesource.com/platform/packages/apps/CertInstaller
Found in HEAD commit: 98f7cb22860f0745444d007924572cbde3b44bdb
Found in base branch: master
Vulnerability Details
In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Publish Date: 2025-12-08
URL: CVE-2025-48580
CVSS 3 Score Details (7.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Step up your Open Source Security Game with Mend here
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource