In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
https://www.theregister.com/2025/12/02/android_0_days/
https://www.securityweek.com/androids-december-2025-updates-patch-two-zero-days/
https://www.malwarebytes.com/blog/news/2025/12/google-patches-107-android-flaws
https://www.infosecurity-magazine.com/news/google-patches-android-0day/
https://www.helpnetsecurity.com/2025/12/02/android-cve-2025-48633-cve-2025-48572/
https://thehackernews.com/2025/12/google-patches-107-android-flaws.html
https://cyberscoop.com/android-security-update-december-2025/
https://github.com/Ashwesker/Blackash-CVE-2025-48633
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48633
https://source.android.com/security/bulletin/2025-12-01
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201737
https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93