CVE-2025-48631

Published Dec 8, 2025

Last updated 2 months ago

Overview

Description
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Modified
Products
android

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-400

Social media

Hype score
Not currently trending
  1. Check out my latest article: CVE-2025-48631 — Android Denial-of-Service Vulnerability https://t.co/uOEtqAZiDo via @LinkedIn

    @Mania4Pakistan

    18 Feb 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. NCERT has issued an advisory about Zero-day attack exploitation on Android devices. These vulnerabilities are majorly deployed to tie surveillance and spyware operations. Includes following: CVE-2025-48633 CVE-2025-48572 CVE-2025-48631 Update ur phones to latest security patch.

    @notsocoolusman

    23 Jan 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Androidで重大な脆弱性と2件のゼロデイ- 12月セキュリティパッチで緊急修正(CVE-2025-48631,CVE-2025-48633,CVE-2025-48572) https://t.co/CjVBuo8h97 #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    4 Dec 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Vulnerabilidades en productos Android ❗ CVE-2025-48631 ❗ CVE-2025-48572 ❗ CVE-2025-48533 ➡️ Más info: https://t.co/FgS6JLtQmr https://t.co/t7uPFASFFb

    @CERTpy

    3 Dec 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ @Google December Android update fixes 107 vulnerabilities, including 2 Framework bugs already exploited in the wild. • CVE-2025-48633 – info disclosure • CVE-2025-48572 – privilege escalation • + a critical DoS flaw: CVE-2025-48631 Have you updated your devices

    @TechNadu

    3 Dec 2025

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Vulnerability Alert — Android December 2025 Google patched 107 Android flaws, including two Framework vulnerabilities (CVE-2025-48633, CVE-2025-48572) exploited in the wild and a critical DoS issue (CVE-2025-48631). Google notes signs of limited, targeted exploitation. https:/

    @CloneSystemsInc

    2 Dec 2025

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔐 تحديث أمان جديد من #Google يعالج 107 ثغرة في Android، بينها ثغرتان صفرية تم استغلالها فعلًا ⚠️ 🛡️ أخطرها: • CVE-2025-48633 → تسريب معلومات • CVE-2025-48572 → رفع صلاحيات

    @Infoandtech3

    2 Dec 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.