---
id: CVE-2025-48637
title: >-
  In multiple functions of mem_protect.c, there is a possible out of bounds
  write due to an integer overflow
summary: >-
  In multiple functions of mem_protect.c, there is a possible out of bounds
  write due to an integer overflow. This could lead to local escalation of
  privilege with no additional execution privileges needed. User interaction is
  not needed f…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
  - CWE-190
vendor: google
product: android
affected:
  - android
published: '2025-12-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48637'
references:
  - url: >-
      https://android.googlesource.com/kernel/common/+/4cfc9c2d8815577832cafbfcd7f98025f0da718d
    label: security@android.com
  - url: >-
      https://android.googlesource.com/kernel/common/+/aff2255dbe38dc7c57bac8d3ba9feed989289b20
    label: security@android.com
  - url: 'https://source.android.com/security/bulletin/2025-12-01'
    label: security@android.com
tags:
  - nvd
epss: 0.00106
epssPercentile: 0.01017
ingestedAt: '2026-09-30T17:13:20.750Z'
---

## Overview

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
