216.73.217.22

CVE-2025-48629

· Published 08/12/2025 17:16 · Modified 08/12/2025 21:16

Labels: CVE-2025-48629 2025-12-08CVE-2025-48629CWE-1188[email protected]

Essential information

Published
08/12/2025 17:16
Modified
08/12/2025 21:16
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD status

Status
Modified — CVE has been amended by a source (CVE Primary CNA or another CNA). Analysis data supplied by the NVD may be no longer be accurate due to these changes.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
google / android cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
google / android cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
google / android cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
google / android cpe:2.3:o:google:android:16.0:*:*:*:*:*:*:*

References