CVE-2025-48561Active Exploitation(google / android)

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for google android systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-203

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
android

4 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-18: 1Active Exploitation · 2026-03-18: 1Technical Details · 2026-03-18: 103-18
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Amelius@Amelius11843670
    Active Exploitation

    GPU side-channel attacks (e.g., Pixnapping, CVE-2025-48561): Malicious Android apps exploit GPU rendering timing to reconstruct on-screen data (e.g., 2FA codes, messages) by analyzing how pixels are processed.

    Post summary

    CVE‑2025‑48561 exposes a GPU rendering timing side‑channel that malicious Android apps can exploit to read on‑screen data, indicating active exploitation in the wild.

    0000088
    11 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid13.0--
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--

Explore more