In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://source.android.com/docs/security/bulletin/2026/2026-04-01 | Vendor Advisory |
Configurations
History
10 Apr 2026, 18:56
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
| References | () https://source.android.com/docs/security/bulletin/2026/2026-04-01 - Vendor Advisory | |
| First Time |
Google android
|
|
| CWE | NVD-CWE-noinfo |
08 Apr 2026, 19:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |
07 Apr 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) StrongBox in Android before security patch level 2026-04-05 has a vulnerability of High Severity, aka A-434039170, A-467765081, A-467765894, and A-467762899. |
06 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 19:16
Updated : 2026-04-13 21:16
NVD link : CVE-2025-48651
Mitre link : CVE-2025-48651
CVE.ORG link : CVE-2025-48651
JSON object : View
Products Affected
- android
CWE
