Two CVEs Identified for Local Privilege Escalation Vulnerabilities

Two CVEs Identified for Local Privilege Escalation Vulnerabilities

First seen 3 Mar 2026, 22:11 UTC Nvd.Nist 71% similarity 29.5

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been reported that allow local escalation of privilege without user interaction. CVE-2025-48636, related to a path traversal error in BugreportContentProvider.java, and CVE-2025-32313, due to an out of bounds write in UsageEvents.java, both require no additional execution privileges for exploitation. Affected software details are being sought.

ThreatCluster AI

Timeline

2026-03-02
CVE-2025-48636 published
2026-03-02
CVE-2025-32313 published
Recent
Vulnerabilities reported with no patches available

Community

Browse all →