CVE-2025-48615

HIGH WAF: Medium
CVSS 7.8 Published: 2025-12-08
CWE-400

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
googleandroid13.0
googleandroid14.0
googleandroid15.0
googleandroid16.0

References

Back to CVE Database