CVE-2025-48609 Details
Description
In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
A path traversal vulnerability in the MmsProvider component of Android allows for the arbitrary deletion of files related to telephony, SMS, and MMS functionalities. This issue could cause a local denial-of-service condition, disrupting these communication services. The vulnerability arises from improper handling of file paths, which could be exploited to delete critical files without requiring additional execution privileges or user interaction.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://source.android.com/docs/security/bulletin/2026/2026-03-01 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 14.0 15.0 16.0 - |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 3, 2026 | Initial Analysis | [email protected] |
| Mar 3, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | New CVE Received | [email protected] |