ZeroHour

CVE-2025-48633

KEVmass

Android Framework Device-Owner Logic Error Exploited in the Wild (CVE-2025-48633)

CISA: Android Framework Information Disclosure Vulnerability

CVSS 3.1
5.5 medium
EPSS
<1%p18
Published
()
KEV added
AI analysis

CVE-2025-48633 is a logic error in the hasAccountsOnAnyUser function of DevicePolicyManagerService.java in the Android Framework that can allow a Device Owner to be added after device provisioning has already completed. An attacker needs only low local privileges and no user interaction to trigger the flaw, which Google's description says could lead to local escalation of privilege; CISA catalogs it as an information disclosure issue, and the CVSS score (C:H/I:N/A:N) reflects high confidentiality impact. All Android devices running the affected Framework code are exposed, with provisioned and enterprise-managed devices the most relevant concern, though no specific affected version range is provided in the available data. Google patched the bug in its latest Android security update alongside 106 other vulnerabilities, including a second actively exploited Framework flaw, CVE-2025-48572. The vulnerability is confirmed exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on December 2, 2025; ransomware use is unknown and no public proof-of-concept is available.

What to do: Install Google's latest Android monthly security update (December 2025), which fixes CVE-2025-48633 and the related CVE-2025-48572; there is no workaround since the flaw needs no user interaction. Organizations running MDM/EMM should prioritize updates on provisioned and corporate devices and verify that no unexpected Device Owner was added after provisioning. US federal agencies must apply the fix per CISA BOD 22-01 following the December 2, 2025 KEV addition.

Affected
Google Android (Framework component, DevicePolicyManagerService)
Estimated exposure
mass≈3 billion+ active Android devices (Google's publicly stated global Android installed base) — The Android Framework ships across Google's fleet of over 3 billion active Android devices, so the plausibly affected population is on the order of billions of devices/users, though the exact affected version subset is not specified in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CISA Known Exploited Vulnerability
Affected
Android Framework
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
google
Products
android
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news