---
id: CVE-2025-48629
title: >-
  In findAvailRecognizer of VoiceInteractionManagerService.java, there is a
  possible way to become the default speech recognizer app due to an insecure
  default value
summary: >-
  In findAvailRecognizer of VoiceInteractionManagerService.java, there is a
  possible way to become the default speech recognizer app due to an insecure
  default value. This could lead to local escalation of privilege with no
  additional exec…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1188
  - CWE-1188
vendor: google
product: android
affected:
  - android = 13.0
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48629'
references:
  - url: 'https://source.android.com/security/bulletin/2025-12-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00082
epssPercentile: 0.00205
ingestedAt: '2026-09-30T17:13:20.749Z'
---

## Overview

In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 13.0`
- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
