CVE-2025-48629
HIGHDescription
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Is your site exposed to CVE-2025-48629?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| android | |
| android | |
| android |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-48629? +
How severe is CVE-2025-48629? +
What products are affected by CVE-2025-48629? +
How do I check if I'm vulnerable to CVE-2025-48629? +
Related Vulnerabilities
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager …
Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** …
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, …
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the …
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests …
Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named …