CVE-2025-48587

In multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*

History

17 Jun 2026, 09:29

Type Values Removed Values Added
Summary
  • (es) En múltiples funciones de ProfilingService.java, existe una posible denegación de servicio persistente debido a una validación de entrada incorrecta. Esto podría llevar a una denegación de servicio local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación.

06 Mar 2026, 04:15

Type Values Removed Values Added
References
  • {'url': 'https://source.android.com/security/bulletin/2026-03-01', 'tags': ['Broken Link'], 'source': 'security@android.com'}
  • () https://source.android.com/docs/security/bulletin/2026/2026-03-01 -

03 Mar 2026, 17:02

Type Values Removed Values Added
First Time Google android
Google
References () https://source.android.com/security/bulletin/2026-03-01 - () https://source.android.com/security/bulletin/2026-03-01 - Broken Link
CPE cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*

02 Mar 2026, 23:16

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.2

02 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 19:16

Updated : 2026-06-17 09:29


NVD link : CVE-2025-48587

Mitre link : CVE-2025-48587

CVE.ORG link : CVE-2025-48587


JSON object : View

Products Affected

google

  • android
CWE
CWE-20

Improper Input Validation