---
id: CVE-2025-48544
title: >-
  In multiple locations, there is a possible way to read files belonging to
  other apps due to SQL injection
summary: >-
  In multiple locations, there is a possible way to read files belonging to
  other apps due to SQL injection. This could lead to local escalation of
  privilege with no additional execution privileges needed. User interaction is
  not needed fo…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: google
product: android
affected:
  - android = 13.0
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2025-09-04'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48544'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-03-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00101
epssPercentile: 0.00845
ingestedAt: '2026-09-30T23:29:32.361Z'
---

## Overview

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 13.0`
- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
