{"id":"ASB-A-443062265","details":"In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-443062265","CVE-2025-48645"],"modified":"2026-04-17T15:55:28.020024Z","published":"2026-03-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2026-03-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/cee45869c491d4e39877918ee881eb60dec7d6e5"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16-qpr2-next:0"},{"fixed":"16-qpr2-next:2026-03-01"}]}],"versions":["16-qpr2-next"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/06a5b2327caa3aa8843496458e98b9bb070df6e5"],"vanir_signatures":[{"signature_version":"v1","digest":{"function_hash":"284873385616894887145484889215867467264","length":247},"id":"ASB-A-443062265-12eae14c","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java","function":"loadDescription"},"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/06a5b2327caa3aa8843496458e98b9bb070df6e5","deprecated":false},{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["155908311954967419277105425701506720436","148790851144830060313721363776235435261","174486574457195345121938167679086002366","131894076854036561559944331517353637741","270321111079142966318976025495022893107"]},"id":"ASB-A-443062265-603490f1","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/06a5b2327caa3aa8843496458e98b9bb070df6e5","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-443062265.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2026-03-01"}]}],"versions":["15"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/2e378635be2c25ffe8c065ae771fc6d1ba74b5c8"],"vanir_signatures":[{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["155908311954967419277105425701506720436","148790851144830060313721363776235435261","174486574457195345121938167679086002366","131894076854036561559944331517353637741","270321111079142966318976025495022893107"]},"id":"ASB-A-443062265-531235e5","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/2e378635be2c25ffe8c065ae771fc6d1ba74b5c8","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"284873385616894887145484889215867467264","length":247},"id":"ASB-A-443062265-8cbbc11a","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java","function":"loadDescription"},"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/2e378635be2c25ffe8c065ae771fc6d1ba74b5c8","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-443062265.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16:0"},{"fixed":"16:2026-03-01"}]}],"versions":["16"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/660101e3cdd2f8e8bc627517691dfb885a5c8302"],"vanir_signatures":[{"signature_version":"v1","digest":{"function_hash":"284873385616894887145484889215867467264","length":247},"id":"ASB-A-443062265-81e7018b","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java","function":"loadDescription"},"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/660101e3cdd2f8e8bc627517691dfb885a5c8302","deprecated":false},{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["155908311954967419277105425701506720436","148790851144830060313721363776235435261","174486574457195345121938167679086002366","131894076854036561559944331517353637741","270321111079142966318976025495022893107"]},"id":"ASB-A-443062265-940dea68","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/660101e3cdd2f8e8bc627517691dfb885a5c8302","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-443062265.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16-qpr2:0"},{"fixed":"16-qpr2:2026-03-01"}]}],"versions":["16-qpr2"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/b879facc3690664e5e53104bf6e296e303e7e77a"],"vanir_signatures":[{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["155908311954967419277105425701506720436","148790851144830060313721363776235435261","174486574457195345121938167679086002366","131894076854036561559944331517353637741","270321111079142966318976025495022893107"]},"id":"ASB-A-443062265-93d26d17","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/b879facc3690664e5e53104bf6e296e303e7e77a","deprecated":false},{"signature_version":"v1","digest":{"function_hash":"284873385616894887145484889215867467264","length":247},"id":"ASB-A-443062265-e28eba3d","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java","function":"loadDescription"},"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/b879facc3690664e5e53104bf6e296e303e7e77a","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-443062265.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2026-03-01"}]}],"versions":["14"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/8402416df645b196d38e8279a02c8efa4f12ba7d"],"vanir_signatures":[{"signature_version":"v1","digest":{"function_hash":"284873385616894887145484889215867467264","length":247},"id":"ASB-A-443062265-04351821","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java","function":"loadDescription"},"signature_type":"Function","source":"https://android.googlesource.com/platform/frameworks/base/+/8402416df645b196d38e8279a02c8efa4f12ba7d","deprecated":false},{"signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["155908311954967419277105425701506720436","148790851144830060313721363776235435261","174486574457195345121938167679086002366","131894076854036561559944331517353637741","270321111079142966318976025495022893107"]},"id":"ASB-A-443062265-5c11c55a","target":{"file":"core/java/android/app/admin/DeviceAdminInfo.java"},"signature_type":"Line","source":"https://android.googlesource.com/platform/frameworks/base/+/8402416df645b196d38e8279a02c8efa4f12ba7d","deprecated":false}],"spl":"2026-03-01","severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-443062265.json"}}],"schema_version":"1.7.5"}