Improper input validation in Google Android - CVE-2025-48543
Published: September 2, 2025 / Updated: September 17, 2025
Vulnerability identifier: #VU114684
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48543
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation within the Android Runtime ART component. A local application can escalate privileges on the system.
Note, the vulnerability is being exploited in the wild.
Affected software
Google Android
Samsung Mobile Firmware
Samsung Mobile Firmware
How to mitigate CVE-2025-48543
Install security update from vendor's website.
Google Android - addressed in versions 13 2025-09-01, 14 2025-09-01, 15 2025-09-01, 16 2025-09-01
Samsung Mobile Firmware - update to SMR-SEP-2025
Samsung Mobile Firmware - update to SMR-SEP-2025