Medium severity6.8NVD Advisory· Published Dec 8, 2025· Updated Jun 17, 2026
CVE-2025-48618
CVE-2025-48618
Description
In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6Patches
Vulnerability mechanics
References
2News mentions
3- Malicious SIMs can hijack smartphones, steal files, and lock them onto 2GHelp Net Security · Aug 11, 2026
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT DevicesThe Hacker News · Aug 11, 2026
- Malicious SIMs can shut down phones, steal files, and drag 5G back to 2GThe Register Security · Aug 11, 2026