---
id: CVE-2025-48632
title: >-
  In setDisplayName of AssociationRequest.java, there is a possible way to cause
  CDM associations to persist after the user has disassociated them due to
  improper input validation
summary: >-
  In setDisplayName of AssociationRequest.java, there is a possible way to cause
  CDM associations to persist after the user has disassociated them due to
  improper input validation. This could lead to local escalation of privilege
  with no a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48632'
references:
  - url: >-
      https://android.googlesource.com/platform/frameworks/base/+/de27b16b1af86d4ce18c9134d85b53331a8d2147
    label: security@android.com
  - url: 'https://source.android.com/security/bulletin/2025-12-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00082
epssPercentile: 0.0021
ingestedAt: '2026-09-30T17:13:20.750Z'
---

## Overview

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
