---
id: CVE-2025-48594
title: >-
  In onUidImportance of DisassociationProcessor.java, there is a possible way to
  retain companion application privileges after disassociation due to improper
  input validation
summary: >-
  In onUidImportance of DisassociationProcessor.java, there is a possible way to
  retain companion application privileges after disassociation due to improper
  input validation. This could lead to local escalation of privilege with no
  additi…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48594'
references:
  - url: >-
      https://android.googlesource.com/platform/frameworks/base/+/ea2bcc66534263fac4c337f1a5149704c2262169
    label: security@android.com
  - url: 'https://source.android.com/security/bulletin/2025-12-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00091
epssPercentile: 0.00449
ingestedAt: '2026-09-30T17:13:20.741Z'
---

## Overview

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
