CVE-2025-48651

Published Apr 6, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48651 is a vulnerability identified in StrongBox implementations within the Android operating system. StrongBox functions as Android's hardware-backed secure keystore, providing enhanced protection for cryptographic keys by storing and managing them in a dedicated, tamper-resistant hardware chip. This flaw affects StrongBox implementations from several vendors, including Google, NXP, STMicroelectronics, and Thales. While specific exploitation details are not yet fully public, StrongBox vulnerabilities can generally lead to issues such as key extraction, privilege escalation, or denial-of-service conditions.

Description
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Modified
Products
android

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.