CVE-2025-48633
KEVmassAndroid Framework Device-Owner Logic Error Exploited in the Wild (CVE-2025-48633)
CISA: Android Framework Information Disclosure Vulnerability
CVE-2025-48633 is a logic error in the hasAccountsOnAnyUser function of DevicePolicyManagerService.java in the Android Framework that can allow a Device Owner to be added after device provisioning has already completed. An attacker needs only low local privileges and no user interaction to trigger the flaw, which Google's description says could lead to local escalation of privilege; CISA catalogs it as an information disclosure issue, and the CVSS score (C:H/I:N/A:N) reflects high confidentiality impact. All Android devices running the affected Framework code are exposed, with provisioned and enterprise-managed devices the most relevant concern, though no specific affected version range is provided in the available data. Google patched the bug in its latest Android security update alongside 106 other vulnerabilities, including a second actively exploited Framework flaw, CVE-2025-48572. The vulnerability is confirmed exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on December 2, 2025; ransomware use is unknown and no public proof-of-concept is available.
What to do: Install Google's latest Android monthly security update (December 2025), which fixes CVE-2025-48633 and the related CVE-2025-48572; there is no workaround since the flaw needs no user interaction. Organizations running MDM/EMM should prioritize updates on provisioned and corporate devices and verify that no unexpected Device Owner was added after provisioning. US federal agencies must apply the fix per CISA BOD 22-01 following the December 2, 2025 KEV addition.
| Google Android (Framework component, DevicePolicyManagerService) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected
- Android Framework
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- android
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N