CVE-2025-48588
Beschrijving NL
In startAlwaysOnVpn van Vpn.java is er een mogelijke manier om always-on VPN uit te schakelen vanwege een logische fout in de code. Dit kan leiden tot lokale escalatie van privileges zonder dat er extra uitvoerende privileges nodig zijn. Gebruikersinteractie is niet nodig voor exploitatie.
Origineel (Engels) tonen
In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.