HIGH
CVE-2025-48543
CVSS
8.8
KEV
Description
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Summary dbcve.org
A use-after-free vulnerability in multiple locations within Chrome's Android sandbox allows escaping the sandbox to attack the Android system_server, achieving local privilege escalation without user interaction or additional execution privileges.
Mitigation
Apply the latest Chrome security update for Android to patch the use-after-free vulnerability in the sandbox. Organizations should ensure Chrome is updated across managed Android devices.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
0.53%
Probability of exploitation in next 30 days
43.8th percentile
References
https://android.googlesource.com/platform/art/+/444fc40dfb04d2ec5f74c443ed3a4dd45d3131f2
Patch, Product
https://source.android.com/security/bulletin/2025-09-01
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48543
Third Party Advisory, US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.