Skip to content
Two CVEs Identified for Local Privilege Escalation Vulnerabilities

Two CVEs Identified for Local Privilege Escalation Vulnerabilities

First seen 3 Mar 2026, 22:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Two vulnerabilities have been reported that allow local escalation of privilege without user interaction. CVE-2025-48636, related to a path traversal error in BugreportContentProvider.java, and CVE-2025-32313, due to an out of bounds write in UsageEvents.java, both require no additional execution privileges for exploitation. Affected software details are being sought.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

Timeline

2026-03-02
CVE-2025-48636 published
2026-03-02
CVE-2025-32313 published
Recent
Vulnerabilities reported with no patches available

More articles in this cluster (2)

Following this threat?

Track CVE-2025-32313 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed