GHSA-m4rp-8c25-g2hrHighCVSS 7.8
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence...
🔗 CVE IDs covered (1)
📋 Description
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2025-48615
- https://android.googlesource.com/platform/frameworks/base/+/a5795fc0cf1f21da88cf05ad06610d3653d1be0e
- https://source.android.com/security/bulletin/2025-12-01
- https://source.android.com/docs/security/bulletin/2026/2026-06-01
- https://github.com/advisories/GHSA-m4rp-8c25-g2hr