CVE-2025-48598
📋 TL;DR
This vulnerability allows an attacker to modify the primary user's face unlock settings without authentication through a confused deputy attack. It affects Android devices with face unlock functionality. Exploitation requires physical access but no user interaction.
💻 Affected Systems
- Android devices with face unlock
📦 What is this software?
Android by Google
⚠️ Risk & Real-World Impact
Worst Case
An attacker with brief physical access could disable or reconfigure face unlock, potentially gaining unauthorized device access or locking out the legitimate owner.
Likely Case
Malicious actor temporarily accessing device could disable biometric security, leaving device vulnerable to further attacks.
If Mitigated
With proper physical security controls, risk is limited to authorized personnel with device access.
🎯 Exploit Status
No user interaction needed, but requires physical device access. Exploit details not publicly available.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: December 2025 Android Security Patch or later
Vendor Advisory: https://source.android.com/security/bulletin/2025-12-01
Restart Required: Yes
Instructions:
1. Check for system updates in Settings > System > System update. 2. Install December 2025 security patch or later. 3. Reboot device after installation.
🔧 Temporary Workarounds
Disable Face Unlock
androidTemporarily disable face unlock feature until patch is applied
Navigate to Settings > Security > Face unlock and disable
Use Stronger Authentication
androidEnable PIN/password as primary unlock method
Settings > Security > Screen lock > Set PIN or Password
🧯 If You Can't Patch
- Implement strict physical security controls for devices
- Disable face unlock and use PIN/password authentication exclusively
🔍 How to Verify
Check if Vulnerable:
Check Android security patch level in Settings > About phone > Android version. If before December 2025, device is vulnerable if face unlock is enabled.
Check Version:
Settings > About phone > Android version > Security patch level
Verify Fix Applied:
Verify security patch level shows December 2025 or later in Settings > About phone > Android version.
📡 Detection & Monitoring
Log Indicators:
- Unexpected changes to biometric settings in system logs
- Face unlock configuration changes without user authentication
Network Indicators:
- None - local physical attack only
SIEM Query:
Search for biometric configuration changes in Android device logs without corresponding user authentication events