CVE-2025-48561

MEDIUM

Multiple Locations - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-48561. PoCs published by thanhvan205.

AI-analyzed exploit summary The repository claims to address CVE-2025-48561 but provides no actual exploit code or technical details about the vulnerability. Instead, it promotes a proprietary security framework with vague marketing language and external download links.

Description

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (1)

nomisec SUSPICIOUS
by thanhvan205 · poc
https://github.com/thanhvan205/Pixnapping-Key-Exfiltration

The repository claims to address CVE-2025-48561 but provides no actual exploit code or technical details about the vulnerability. Instead, it promotes a proprietary security framework with vague marketing language and external download links.

Classification
Suspicious 95%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: N/A
No auth needed
devstral-2 · analyzed Apr 15, 2026 Full analysis →

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (4)
google/android 13.0
google/android 14.0
google/android 15.0
google/android 16.0
Published Sep 04, 2025
Tracked Since Feb 18, 2026