In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
                
            References
                    | Link | Resource | 
|---|---|
| https://android.googlesource.com/platform/packages/modules/IntentResolver/+/923a5673ac9d4b366097a8912a04e40e85111ed4 | Product Patch | 
| https://source.android.com/security/bulletin/2025-09-01 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    05 Sep 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Google Google android | |
| CPE | cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* | |
| References | () https://android.googlesource.com/platform/packages/modules/IntentResolver/+/923a5673ac9d4b366097a8912a04e40e85111ed4 - Product, Patch | |
| References | () https://source.android.com/security/bulletin/2025-09-01 - Vendor Advisory | 
05 Sep 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-266 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.0 | 
04 Sep 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-04 19:15
Updated : 2025-09-05 19:15
NVD link : CVE-2025-48526
Mitre link : CVE-2025-48526
CVE.ORG link : CVE-2025-48526
JSON object : View
Products Affected
                - android
CWE
                
                    
                        
                        CWE-266
                        
            Incorrect Privilege Assignment
