CVE-2025-48633Medium· 5.5▾ Midnight⚠ Exploited in the wild0dayIn hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 30.3 · likelihood 0.1 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Federal remediation due Dec 23, 2025
Disclosed via NVD
Last analysed / modified upstream
0.3%
Added to the CISA catalog on Dec 2, 2025. Federal remediation due Dec 23, 2025. View catalog ↗
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
android = 13.0android = 14.0android = 15.0android = 16.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0016Low· 3.3In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass
CVE-2026-0017High· 7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code
CVE-2026-0019High· 7.8In SettingsLib, there is a possible way to disable system components due to a logic error in the code
CVE-2026-0018Medium· 5.5In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation
CVE-2025-58477Medium· 4.3Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
CVE-2025-58478Medium· 4.3Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.