Description
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-03-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability stems from improper input validation in the loadDescription method of DeviceAdminInfo.java, which can cause information from a persistent package to be handled incorrectly. This flaw allows an attacker with local access to elevate privileges on the affected device without needing to execute additional code. The weakness is classified as CWE‑269, referring to improper privilege management. The consequence is a full compromise of the device’s security model, granting the attacker the same rights as the device’s root or system processes, and providing potential for further malicious activity.

Affected Systems

Android devices running any of the following versions are affected: Android 14.0, Android 15.0, Android 16.0, and the Android 16.0 QPR2 beta releases (1, 2, and 3). These are identified by the provided CPE strings and correspond to all modern Android builds in the listed series.

Risk and Exploitability

The CVSS score of 9.8 signals a critical security impact. The EPSS score of less than 1% indicates that real‑world exploitation is considered low at present, though the flaw remains available. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw locally; no additional privileges or remote access are required, and no user interaction is necessary, making the attack vector essentially local device access.

Generated by OpenCVE AI on April 22, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Android security patch released by Google in the March 2026 security bulletin, which fixes the input‑validation issue in DeviceAdminInfo.
  • Disable or revoke any device administrator rights for applications that are not essential to device operation, thereby limiting the potential impact of a local privilege escalation.
  • Keep the device updated to the latest Android security patch level to ensure ongoing protection against this and other emerging vulnerabilities.

Generated by OpenCVE AI on April 22, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
Title Persistent Package Leading to Local Privilege Escalation via Improper Input Validation in DeviceAdminInfo

Fri, 06 Mar 2026 04:30:00 +0000

Type Values Removed Values Added
References

Fri, 06 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
References

Tue, 03 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:*

Tue, 03 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 03 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:*
cpe:2.3:o:google:android:16.0:qpr2:*:*:*:*:*:*
Vendors & Products Google
Google android
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Mon, 02 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2026-04-21T02:41:36.807Z

Reserved: 2025-05-22T18:12:46.994Z

Link: CVE-2025-48645

cve-icon Vulnrichment

Updated: 2026-03-03T14:51:39.235Z

cve-icon NVD

Status : Modified

Published: 2026-03-02T19:16:28.320

Modified: 2026-03-06T04:16:00.723

Link: CVE-2025-48645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T11:30:15Z

Weaknesses