CVE-2025-48626Critical· 9.8▾ MidnightIn multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User inter…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
android = 13.0android = 14.0android = 15.0android = 16.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0017High· 7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code
CVE-2026-58766High· 7.8In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0186Medium· 6.7In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0187Medium· 6.7In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0189High· 8.4In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code
CVE-2026-55359High· 7.8In multiple locations, there is a possible permission bypass due to a logic error in the code