{"cve_id":"CVE-2025-48633","summary":"In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"epss":0.00137,"ranking_epss":0.33536,"kev":true,"propose_action":"Android Framework contains an unspecified vulnerability that allows for information disclosure.","ransomware_campaign":"Unknown","references":["https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93","https://source.android.com/security/bulletin/2025-12-01","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48633"],"published_time":"2025-12-08T17:16:19","cpes":["cpe:2.3:o:google:android:13.0","cpe:2.3:o:google:android:14.0","cpe:2.3:o:google:android:15.0","cpe:2.3:o:google:android:16.0"]}