Description
In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-01
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from a logic flaw within KeyguardViewMediator.java in the Android operating system. This flaw enables an attacker to bypass lockdown mode that is normally enforced by screen pinning. Because the exploit does not require additional execution privileges or user interaction, a local attacker can use it to reveal sensitive information normally concealed in lockdown mode, leading to local information disclosure.

Affected Systems

Google’s Android platform is affected. The issue is present in the KeyguardViewMediator component across all versions of Android that have not yet integrated the corrective logic, impacting devices that use screen pinning for lockdown protection. Exact version ranges are not specified, so all current Android releases should be considered potentially vulnerable until an official fix is released.

Risk and Exploitability

The flaw can be exploited locally without user involvement, making it a high‑risk condition for devices that rely on lockdown mode for protecting data. The EPSS value is not available, and the vulnerability is not listed in CISA’s KEV catalog, so current exploitation statistics are unknown. However, because no additional privileges are required and the logic error permits information disclosure, the potential impact remains significant in environments where sensitive data are protected by lockdown. The CVSS score of 3.3 indicates that the vulnerability is considered low severity.

Generated by OpenCVE AI on June 2, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the next Android security update that addresses the KeyguardViewMediator logic error.
  • If the update is unavailable, disable screen pinning lockdown until a patch is released.
  • Verify device security configuration with Google’s Android Security Bulletin for guidance on temporary mitigations.

Generated by OpenCVE AI on June 2, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
Title KeyguardViewMediator Logic Error Enables Bypass of Lockdown Mode Leading to Local Information Disclosure
Weaknesses CWE-200
CWE-287

Tue, 02 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Title Bypass Lockdown Mode via Logic Error in KeyguardViewMediator Leading to Local Information Disclosure
Weaknesses CWE-703

Tue, 02 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Jun 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Mon, 01 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Bypass Lockdown Mode via Logic Error in KeyguardViewMediator Leading to Local Information Disclosure
First Time appeared Google
Google android
Weaknesses CWE-703
Vendors & Products Google
Google android

Mon, 01 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-01T23:46:54.862Z

Reserved: 2025-05-22T18:12:23.625Z

Link: CVE-2025-48616

cve-icon Vulnrichment

Updated: 2026-06-01T23:46:39.293Z

cve-icon NVD

Status : Received

Published: 2026-06-01T22:16:18.717

Modified: 2026-06-02T00:16:30.930

Link: CVE-2025-48616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T04:00:13Z

Weaknesses