---
id: CVE-2025-48569
title: >-
  In multiple locations, there is a possible permanent denial of service due to
  resource exhaustion
summary: >-
  In multiple locations, there is a possible permanent denial of service due to
  resource exhaustion. This could lead to local denial of service with no
  additional execution privileges needed. User interaction is not needed for
  exploitation.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-400
vendor: google
product: android
affected:
  - android = 16.0
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48569'
references:
  - url: 'https://source.android.com/security/bulletin/android-16-qpr2'
    label: security@android.com
tags:
  - nvd
epss: 0.00073
epssPercentile: 0.00052
ingestedAt: '2026-09-30T17:13:20.751Z'
---

## Overview

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
