In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://source.android.com/security/bulletin/2026-03-01 |
|
History
Mon, 02 Mar 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Mon, 02 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| References |
|
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2026-03-02T22:08:17.377Z
Reserved: 2025-05-22T18:11:40.405Z
Link: CVE-2025-48567
Updated: 2026-03-02T22:07:46.711Z
Status : Awaiting Analysis
Published: 2026-03-02T19:16:25.880
Modified: 2026-03-02T20:29:29.330
Link: CVE-2025-48567
No data.
OpenCVE Enrichment
No data.