{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-48633",
  "revision": 1,
  "title": "Android Framework — device owner can be added after setup",
  "summary": "A logic error in the Android device policy service lets an app add itself as device owner after provisioning has already finished, handing it control the device was never meant to give away.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 5.5,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.00262,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2025-12-02",
    "prerequisites": "An app already installed on the device; no user interaction needed."
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "privilege_escalation",
  "recommended_action": "Install the December 2025 Android security patch level or later; on managed fleets, review which application currently holds the device owner role.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-48633",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-48633",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-48633",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48633",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93"
    },
    {
      "type": "vendor_advisory",
      "url": "https://source.android.com/security/bulletin/2025-12-01"
    }
  ],
  "published_at": "2025-12-08T17:16:19.610Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "android",
    "framework",
    "device-management",
    "privilege-escalation",
    "kev"
  ]
}
