
CVE: CVE-2025-48611 Vendor: Google Product: Pixel CVSS: 10.0 Credits: Canyie(石松洲) of LSPosed Team Description: In DeviceId of http://DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2025-48611 • https://source.android.com/docs/security/bulletin/pixel/2026/2026-03-01 #dbugs_vuln
Post summary
CVE-2025-48611 is a newly disclosed high‑severity vulnerability in Google Pixel's DeviceId, where a missing bounds check allows local privilege escalation without user interaction. References to the vulnerability database and Google's security bulletin are provided.






