High severity8.8CISA KEVNVD Advisory· Published Sep 4, 2025· Updated Jun 17, 2026
CVE-2025-48543
CVE-2025-48543
Description
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
3- android.googlesource.com/platform/art/+/444fc40dfb04d2ec5f74c443ed3a4dd45d3131f2nvdPatchProduct
- source.android.com/security/bulletin/2025-09-01nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
News mentions
1- Critical Remote Code Execution Vulnerability Patched in AndroidSecurityWeek · May 5, 2026