CVE-2025-48631 Details
Description
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
A denial-of-service vulnerability has been identified in the Android Framework's LocalImageResolver component. This issue arises from improper handling of image data, which can lead to excessive resource consumption. The vulnerability allows for remote denial-of-service attacks, requiring no additional privileges or user interaction for exploitation. Affected devices include those running Android versions 13, 14, 15, and 16.
Users can update their devices to the December 2025 security patch level to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://source.android.com/docs/security/bulletin/2026/2026-03-01 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 13.0 14.0 15.0 16.0 - 16.0 qpr2_beta_1 16.0 qpr2_beta_2 16.0 qpr2_beta_3 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 3, 2026 | Modified Analysis | [email protected] |
| Mar 2, 2026 | CVE Modified | [email protected] |
| Dec 8, 2025 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | New CVE Received | [email protected] |