Description
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-06-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing permission check in multiple locations of the Android passkey pairing logic, allowing a third‑party application to trigger passkey entry pairing approval without authorization. This omission enables remote (proximal/adjacent) escalation of privilege, as the attacker can gain higher access rights without needing to obtain additional execution privileges or user interaction. The flaw results in unauthorized privilege escalation that could affect device data and system integrity.

Affected Systems

The affected vendor is Google for the Android operating system. Specific product names are not enumerated, and no version information is available in the current data, so all Android devices manufactured by Google that include the affected passkey pairing functionality are considered potentially vulnerable.

Risk and Exploitability

The EPSS score is reported to be less than 1%, indicating a very low probability of exploitation in the wild at the time of this analysis. The vulnerability is not currently listed in the CISA KEV catalog. However, because it permits privilege escalation without user interaction, an attacker could exploit the flaw by sending a crafted passkey pairing request from a nearby device or network segment, potentially escalating privileges on the target device. The lack of a release‑time patch in the data suggests that the risk remains until an official fix is applied.

Generated by OpenCVE AI on June 17, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Android security update that addresses CVE‑2025‑48640.
  • If the patch is not yet available, mitigate by disabling third‑party passkey pairing or restricting access rights to the pairing APIs through device administration policies.
  • Enable logging for passkey pairing events and monitor for anomalous approvals, investigating any suspicious activity.

Generated by OpenCVE AI on June 17, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Wed, 17 Jun 2026 06:00:00 +0000

Type Values Removed Values Added
Description In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-06-17T13:47:21.701Z

Reserved: 2025-05-22T18:12:39.229Z

Link: CVE-2025-48640

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T07:30:04Z

Weaknesses

No weakness.