CVE Vulnerabilities

CVE-2025-48598

Externally Controlled Reference to a Resource in Another Sphere

Published: Dec 08, 2025 | Modified: Dec 08, 2025
CVSS 3.x
6.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In multiple locations, there is a possible way to alter the primary users face unlock settings due to a confused deputy. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle16.0 (including)16.0 (including)

References