CVE-2025-48543

ENISA EUVD: EUVD-2025-26791 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 4 articles Published: 2025-09-04

EPSS Score

Source: FIRST.org · 2026-05-23
0.31%
probability
This CVE has a 0.31% probability of being exploited in the next 30 days.
0% Top 54.3th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
8.8
HIGH
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

Google
Android
16 15 14 13

Attack Intelligence

Google Project Zero

Patched
Sept. 1, 2025
Reported by
Clément Lecigne of Google's Threat Analysis Group
Root Cause Analysis
???

Exploits & PoC

gamesarchive/CVE-2025-48543

PoC exploit for CVE-2025-48543 in C++

52 2025-12-28
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
88%
EPSS 0.31%
CVSS v3.1 8.8
Mentions 4
Last Seen May 05, 2026

CNA Information

CNA Assigner
google_android

Analyst Note

CVE-2025-48543 is confirmed as a critical sandbox escape vulnerability affecting Android Chrome with CVSS 8.8 (HIGH severity). The vulnerability enables local privilege escalation through a use-after-free flaw without requiring user interaction, and has been documented in Google Project Zero and reported as actively exploited in the wild by TheHackerNews.

Threat Actors 12

Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
APT24
apt_group Information theft and espionage 🇨🇳 CN
UNC1549
apt_group Information theft and espionage 🇮🇷 IR
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
PassCV
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Storm-2460
apt_group 🇷🇺 RU

Triage Info

Decided atMar 03, 2026
Published DateSep 04, 2025