← Retour aux CVEs
CVE-2025-48609
CRITICAL9.1
Description
In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Details CVE
Score CVSS v3.19.1
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/2/2026
Derniere modification3/6/2026
Sourcenvd
Observations honeypot0
Produits affectes
google:android
Faiblesses (CWE)
CWE-400
References
https://source.android.com/docs/security/bulletin/2026/2026-03-01(security@android.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.