In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
| Vendor | Product | Versions |
|---|---|---|
| android | 16-qpr2, 16, 15, 14 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| android | cert_advisory | 90% | |
| samsung | android | cert_advisory | 90% |
Updated description with more technical detail, added affected version 14, and included patch information for June 2026.
Updated the exploitation status to indicate that CVE-2025-48595 may be under limited, targeted exploitation and marked exploit availability as true.
Updated severity from HIGH to CRITICAL and clarified that no exploit is available.
Initial creation