ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google’s latest Android security update fixes two actively exploited flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-47319
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

Information disclosure while exposing internal TA-to-TA communication APIs to HLOS

NVD description · AI analysis pending
6.7<1%
  • qualcomm ar8035 firmware
  • qualcomm fastconnect 6200 firmware
  • qualcomm fastconnect 6700 firmware
  • +1 more
CVE-2025-47372
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.

NVD description · AI analysis pending
8.4<1%
  • qualcomm qam8255p firmware
  • qualcomm qam8620p firmware
  • qualcomm qam8650p firmware
  • +1 more
CVE-2025-48572
+1 in the same advisory: …48633
Local Privilege Escalation in Android Framework Under Active Exploitation

CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%.

Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe.

7.8
group max
<1% KEV
  • Google Android (Framework component)
massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device)
CVE-2025-48623
+3 in the same advisory: …48637 …48638 …48624
In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation.

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
7.8<1%
  • google android
Full article263 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 02, 2025

Google’s latest Android security update fixes 107 flaws across multiple components, including two vulnerabilities actively exploited in the wild.

Google’s new Android update patches 107 vulnerabilities, including two already exploited in the wild, across system, kernel, and major vendor components.

December’s Android update offers two patch levels (12-01, 12-05) for faster fixes across devices.

The two high-severity vulnerabilities that are “under limited, targeted exploitation” are:

  • CVE-2025-48572 – An elevation of privilege vulnerability in Framework
  • CVE-2025-48633 – An information disclosure vulnerability in Framework

As usual, Google did not provide technical details about the attacks exploiting the above vulnerabilities.

The tech giant also addressed the following critical vulnerabilities in the kernel component:

CVEReferencesTypeSeveritySubcomponent
CVE-2025-48623A-436580278
Upstream kernel [2]
EoPCriticalpKVM
CVE-2025-48624A-443053939
Upstream kernel
EoPCriticalIOMMU
CVE-2025-48637A-443763663
Upstream kernel [2]
EoPCriticalpKVM
CVE-2025-48638A-442540376
Upstream kernel [2]
EoPCriticalpKVM

and Qualcomm closed-source components:

CVEReferencesSeveritySubcomponent
CVE-2025-47319A-421905250*CriticalClosed-source component
CVE-2025-47372A-442619421*CriticalClosed-source component

“The most severe of these issues is a critical security vulnerability in the Framework component that could lead to remote denial of service with no additional execution privileges needed.” reads the advisory published by Google. “The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185226/security/googles-latest-android-security-update-fixes-two-actively-exploited-flaws.html