Vulnerability Details CVE-2025-48592
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Exploit prediction scoring system (EPSS) score
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-48592
-
cpe:2.3:o:google:android:15.0
-
cpe:2.3:o:google:android:16.0