Description

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

INFO

Published Date :

2025-09-04T18:34:17.642Z

Last Modified :

2025-09-04T20:22:57.955Z

Source :

google_android
AFFECTED PRODUCTS

The following products are affected by CVE-2025-48538 vulnerability.

Vendors Products
Google
  • Android
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-48538.

CVSS Vulnerability Scoring System