Vulnerability Management, Patch/Configuration Management

Actively exploited zero-days among over 100 addressed Android bugs

(Adobe Stock)

Updates have been released by Google to fix 107 vulnerabilities in Android devices, including a pair of high-severity zero-day issues that may be subjected to limited, targeted exploitation, CyberScoop reports.

Threat actors could harness the Android framework zero-days, tracked as CVE-2025-48633 and CVE-2025-48572, to facilitate information access and privilege escalation, respectively, according to Google. Meanwhile, the most serious of the addressed bugs is the critical Android framework flaw, tracked as CVE-2025-48631, which could be leveraged to enable remote denial of service without the need for more privileges.

Google has divided this month's update, which has the second-most addressed issues after September, into two patch levels, with the first dealing with 37 framework bugs and 14 system weaknesses, and the second managing nine kernel flaws. Also part of the update were patches for dozens of MediaTek, Unisoc, Qualcomm, Arm, and Imagination Technology vulnerabilities.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds