nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-48640 CVE-2025-48640
HIGH
Android Missing Permission Check on Passkey Entry Pairing Approval
Record summary
CVE-2025-48640 has a selected CVSS score of 8.0 (high).
Description
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AndroidBrowse Google / AndroidDefault status: unaffected | CVE List | 17 | affected |
References
2source.android.com
https://source.android.com/docs/security/bulletin/android-17