Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 6 min 124 bronnen 3 kritiek 6 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-48588

HIGH · 7.8 CVSS Gepubliceerd:

Beschrijving NL

In startAlwaysOnVpn van Vpn.java is er een mogelijke manier om always-on VPN uit te schakelen vanwege een logische fout in de code. Dit kan leiden tot lokale escalatie van privileges zonder dat er extra uitvoerende privileges nodig zijn. Gebruikersinteractie is niet nodig voor exploitatie.

Origineel (Engels) tonen

In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendors

Google

Affected products

Android

References