HIGH

CVE-2025-48543

Google Android 2025-09-04 CVSS v3.1
CVSS
8.8
KEV

Description

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Summary dbcve.org

A use-after-free vulnerability in multiple locations within Chrome's Android sandbox allows escaping the sandbox to attack the Android system_server, achieving local privilege escalation without user interaction or additional execution privileges.

Mitigation

Apply the latest Chrome security update for Android to patch the use-after-free vulnerability in the sandbox. Organizations should ensure Chrome is updated across managed Android devices.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

0.53%
Probability of exploitation in next 30 days
43.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE