news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2025-48618

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
6.6 Medium
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk score
52.8
Published
2025-12-08
Status
Published

In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weaknesses

Elevation of privilegeCWE-667

Coverage 2

Advisories and references