Daily digest
Monday 8 December 2025
A heavy day: 74 new CVEs, well above the recent average of about 36. Severity skewed high: 2 critical and 42 high, 59% of the total. 3 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 58.
New this day, ranked by depth score
The 12 that matter most of the 74 published.
CVE-2025-48572High· 7.8CISA KEV0dayIn multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
CVE-2025-48633Medium· 5.5CISA KEV0dayIn hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution …
CVE-2025-48626Critical· 9.8In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User inter…
CVE-2025-27020Critical· 9.8Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.
CVE-2023-53762High· 8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync Use-after-free can occur in hci_disconnect_all_sync if a connection is deleted by concurrent processing of a co…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in hci_disconnect_all_sync Use-after-free can occur in hci_disconnect_all_sync if a connection is deleted by concurrent processing of a co…
CVE-2025-66470Medium· 6.1PoCNiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
CVE-2025-48638High· 7.8In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …
CVE-2025-48637High· 7.8In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow
In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f…
CVE-2025-48632High· 7.8In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation
In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no a…
CVE-2025-48629High· 7.8In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional exec…
CVE-2025-48628High· 7.8In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy
In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…
CVE-2025-48627High· 7.8In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a logic error in the code
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional exec…
Most-affected vendors
By CVEs published in the period.