CVE-2025-48639
🟡 Monitoruj
Atak tapjacking w DefaultTransitionHandler.java może prowadzić do niezamierzonego przyznania uprawnień aplikacji.
CVSS
7.3
EPSS
0.1%
Exploit
none
Vendor
google
Opis źródłowy (NVD)
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-12-08 17:16:19 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 16:10:00 UTC |
Referencje
- https://android.googlesource.com/platform/frameworks/base/+/6d1697c96c5cae5062f6aea58cf2665b7d646cb8 ([email protected]) [Product]
- https://android.googlesource.com/platform/frameworks/native/+/cc34c7b416b964c05a42ae3e9c2929b59b92c64f ([email protected]) [Product]
- https://source.android.com/security/bulletin/2025-12-01 ([email protected]) [Vendor Advisory]