Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

Java DeviceAdminInfo vulnerability allows local privilege escalation

CVE-2025-48645 ASB-A-443062265
Summary

An issue in a Java library allows an attacker to gain higher privileges on a system without needing to interact with the user. This could be exploited by a malicious user with access to the system. To fix the issue, update the affected Java library.

What to do
  • Update google platform/frameworks/base to version 16-qpr2-next:2026-03-01.
  • Update google platform/frameworks/base to version 15:2026-03-01.
  • Update google platform/frameworks/base to version 16:2026-03-01.
  • Update google platform/frameworks/base to version 16-qpr2:2026-03-01.
  • Update google platform/frameworks/base to version 14:2026-03-01.
Affected software
VendorProductAffected versionsFix available
google android 14.0
google android 15.0
google android 16.0
google android 16.0
google android 16.0
google android 16.0
google platform/frameworks/base > 16-qpr2-next:0 , <= 16-qpr2-next:2026-03-01 16-qpr2-next:2026-03-01
google platform/frameworks/base > 15:0 , <= 15:2026-03-01 15:2026-03-01
google platform/frameworks/base > 16:0 , <= 16:2026-03-01 16:2026-03-01
google platform/frameworks/base > 16-qpr2:0 , <= 16-qpr2:2026-03-01 16-qpr2:2026-03-01
google platform/frameworks/base > 14:0 , <= 14:2026-03-01 14:2026-03-01
Original title
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution pr...
Original description
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd CVSS3.1 7.8
Vulnerability type
CWE-269 Improper Privilege Management
Published: 1 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026