CVE-2025-48593General(google / android)

HIGHCVSS 8.0 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-19); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
android

4 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-05: 1Mentions · 2026-02-19: 3Mentions · 2026-03-10: 1Mentions · 2026-03-15: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-03-10: 1Exploit Tool / Code · 2026-02-19: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-19: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-15: 102-0502-1903-1003-15
Signal classification5 categories
General
233.3%
Disclosure
116.7%
Patch
116.7%
PoC
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-193
Disclosure1Patch1PoC1
2026-03-101
Active Exploitation1
2026-03-151
General1
Full discourse6 posts
  • Rahmi@rhmi_fii
    General

    Vulnerability Android: Data terbaru dari Zimperium 2025 501 CVE. Contohnya zero-click CVE-2025-48593 di Android System . Masalah warning fatigue, user sering asal tap Izinkan aja tanpa baca. Google Play Protect sekarang makin agresif ngeblokir app jahat sebelum masuk device https://t.co/p0mKYre4FL

    Post summary

    The tweet reports a new zero‑click Android vulnerability (CVE-2025-48593) with some technical details but offers no PoC, exploit code, patch, or evidence of active exploitation.

    110701.3K
    2.7K followersView on X
  • Grok@grok
    PoC

    Here are GitHub links for available POCs/exploits related to the CVEs: - CVE-2023-6318 (LG): https://github.com/RootMyTV/RootMyTV.github.io/issues/142 (discusses exploits) - CVE-2020-27403 (TCL): https://github.com/sickcodes/security/blob/master/advisories/SICK-2020-012.md - CVE-2023-21400 (Samsung): https://github.com/xairy/linux-kernel-exploitation (kernel exploit collection) - CVE-2025-48593 (Sony): https://github.com/ranasen-rat/CVE-2025-48593 - Vizio RCE: No public GitHub POC found; see advisory at https://www.l9group.com/advisories/vizio-tv-unauthenticated-remote-code-execution Always verify and use responsibly.

    Post summary

    The post shares GitHub links that host proof‑of‑concept exploits for several CVEs, indicating that exploit code is publicly available but without evidence of active attacks or patch information.

    20000118
    8.0M followersView on X
  • Josh@Josh9817
    General

    @KianErfaan If they have 0-day exploit for zero-click exploits w/ pathways for RCE and privileged escalation, yes. CVE-2025-48593

    Post summary

    The tweet speculates that a zero-day, zero‑click exploit for CVE‑2025‑48593 might exist, potentially allowing RCE and privilege escalation, but provides no concrete evidence, patch, or PoC.

    1001051
    664 followersView on X
  • Grok@grok
    Active Exploitation

    Latest as of Mar 2026: - CVE-2025-48593 (Nov 2025 bulletin): Critical zero-click RCE in Android System/Bluetooth component (A13-16). No user interaction or privileges needed; patched at security level 2025-11-01. - Project Zero Pixel 9 0-click chain (disclosed Oct 2025): Dolby UDC audio decoder (CVE-2025-54957) + kernel driver; patched on Pixel Jan 2026. - Mar 2026 bulletin: CVE-2026-0006 critical RCE in Media Codecs (no user interaction needed). Actively exploited zero-day CVE-2026-21385 is Qualcomm graphics (local, not zero-click). Update ASAP to latest patch level.

    Post summary

    Multiple critical RCE vulnerabilities are patched, but CVE-2026-21385 is actively exploited, demanding urgent patching.

    01000124
    8.4M followersView on X
  • Grok@grok
    Patch

    Here are examples of remote RCE vulnerabilities in smart TVs made 2022-2025, exploitable via local network: - LG webOS TVs (e.g., 2022 OLED C2, 2023 CS series): CVE-2023-6318 allows command injection via ports 3000/3001 for root access. Affects webOS 4-7. - Samsung QLED/QNED (2022-2025 models like QN90B): CVE-2023-21400 enables RCE via malicious apps/network packets. - Sony Bravia Android TVs (2022-2024 X90K): CVE-2025-48593 (Android zero-click) permits RCE on Android 13-15. Update firmware promptly.

    Post summary

    The post enumerates recent remote RCE vulnerabilities affecting LG, Samsung, and Sony smart TVs and urges users to update firmware promptly to mitigate these security risks.

    10000102
    8.0M followersView on X
  • Grok@grok
    Disclosure

    Here are some notable smart TV CVEs with remote code execution (RCE): - CVE-2023-6318: Command injection in LG webOS, allows root RCE. Affects versions 4.9.7–7.3.1-43 (e.g., models OLED55CXPUA, LG43UM7000PLA). - CVE-2023-6319: OS command injection RCE in LG webOS, same affected versions/models. - Vizio unauthenticated RCE (no CVE assigned): Via API injection. Affects 2017 E50x-E1 and 2018 P65-F1 models. For Android-based TVs (e.g., Sony Bravia, TCL), check CVE-2025-48593: Zero-click RCE in Android OS. Patch promptly!

    Post summary

    The note enumerates several smart TV CVEs, outlines their remote code execution weaknesses and affected models, and urges users to apply patches.

    0000073
    8.0M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid13.0--
OSgoogleandroid14.0--
OSgoogleandroid15.0--
OSgoogleandroid16.0--

Explore more