Vulnerabilities
CVE-2025-48647 - Google CPM Firmware Tracepoint IPC Memory Overwrite Local Privilege Escalation
CVE ID : CVE-2025-48647 Published : Jan. 16, 2026, 7:16 p.m. | 1 hour, 1 minute ago Description : In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...