Google addresses six vulnerabilities in August’s Android security update
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-48530 | In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remote code execution in combination with other bugs, with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 8.1 group max | <1% |
| — |
Full article568 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Android partners and customers have experienced a temporary respite from double-digit vulnerabilities this summer. Google issued no security patches in its update last month.
Listen to this article
0:00
Learn more.
Google addressed six vulnerabilities affecting Android devices in its August security update, marking a months-long lull in the number of software defects disclosed and patched in the mobile operating system this summer.
The company issued no security patches in its update last month. Yet, monthly Android security bulletins typically address dozens of vulnerabilities. Google’s Android security update covered 34 vulnerabilities in June, 47 defects in May, 62 in April and 43 in March.
The summer break suggests Android partners and customers have experienced a temporary respite from a larger pool of vulnerabilities. Google notifies Android partners of all software defects affecting the mobile operating system at least a month before public disclosure.
Google said the most severe defect in this month’s security update — CVE-2025-48530 — is a critical remote code execution vulnerability in the Android system that doesn’t require user interaction or additional execution privileges for exploitation.
The advisory also addressed two high-severity vulnerabilities — CVE-2025-22441 and CVE-2025-48533 — affecting the Android framework. Google said user interaction and additional privileges aren’t required to exploit the elevation of privilege defects.
None of the vulnerabilities addressed in this month’s security update are under active exploitation, according to Google. The company hasn’t included an actively exploited defect in its monthly batch of patches since May.
The Android security update contains two patch levels — 2025-08-01 and 2025-08-05 — allowing Android partners to address common vulnerabilities on different devices.
The second patch includes fixes for a high-severity vulnerability affecting Arm components and two vulnerabilities in Qualcomm components.
Third-party Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.
Google said source code patches for all six vulnerabilities addressed in this month’s security update will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-august-2025/