CVE-2025-48646 | Google Android 14/15/16/16-qpr2 ActivityStarter.java executeRequest confused deputy (WID-SEC-2026-0569)
A vulnerability classified as problematic has been found in Google Android 14/15/16/16-qpr2. Affected by this issue is the function executeRequest of the file ActivityStarter.java. Performing a manipulation results in unintended intermediary.
This vulnerability is cataloged as CVE-2025-48646. The attack must be initiated from a local position. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.