VulnCity

Android Framework Privilege Escalation (1)

  • شناسه CVE: CVE-2025-48633
  • شدت: بالا
  • امتیاز CVSS: 8.4
  • فروشنده/سازنده: Google (Android)
Privilege EscalationAndroidFrameworkMobile
A privilege escalation vulnerability in the Android Framework that allows a malicious application to gain elevated privileges without user interaction.

## Vulnerability Overview
This vulnerability in the Android Framework's Activity Manager service allows a malicious app to escalate its privileges to system-level access. The flaw exists in the handling of pending intents and broadcast receivers, where a crafted intent can bypass permission checks and execute privileged operations.

## Technical Details
- **Type:** Privilege Escalation (CWE-269)
- **Root Cause:** Improper validation of caller identity in the PendingIntent resolution process. A malicious app can create a PendingIntent that, when resolved, executes with the privileges of the system_server process.
- **Attack Vector:** Local — requires installation of a malicious application
- **No User Interaction Required** after app installation

## Active Exploitation
- Google has confirmed active exploitation in the wild.
- Used in targeted surveillance operations.
- Commercial spyware vendors reported to have incorporated this exploit.

## Impact
- Escalation from normal app privileges to system privileges
- Access to all user data (contacts, messages, photos, location)
- Silent installation of additional malware
- Bypass of Android security controls and permissions

## Affected Versions
- Android 12, 12L, 13, 14 (before February 2025 security patch)

نرم‌افزارهای تحت تأثیر

  • Android 12
  • Android 13
  • Android 14