CVE-2025-48633
Android Framework Information Disclosure Vulnerability
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
MEDIUM · CVSS 5.5
⚠ CISA KEV
EPSS 0.00097
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
Sigma rules0
YARA rules0