← Back to browse · API

CVE-2025-48633

Severity
MEDIUM
CVSS
5.5
EPSS
0.00256
Risk score
47.09
CISA KEV
Yes
PoC
No
Published
2025-12-08
Modified
2026-02-26
First seen
2026-08-07
Aliases
CNVD-2025-31463, EUVD-2025-201737, GHSA-2JV4-596W-G9HJ
Products
Android:Framework, Google Android 13.0, Google Android 14.0, Google Android 15.0, Google Android 16.0, Google:Android 13, Google:Android 14, Google:Android 15, Google:Android 16
Sources
cnvd CNVD-2025-31463
cisa.gov CVE-2025-48633
euvd EUVD-2025-201737

Description

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References