ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Google Releases Patches for Zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-48633CVE-2025-48572CVE-2025-48631

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48572
+1 in the same advisory: …48633
Local Privilege Escalation in Android Framework Under Active Exploitation

CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%.

Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe.

7.8
group max
<1% KEV
  • Google Android (Framework component)
massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device)
CVE-2025-48631
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion.

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

NVD description · AI analysis pending
6.5<1%
  • google android
Full article228 words · extracted from infosecurity-magazine.com · click to collapse

In its latest Android Security Bulletin, Google disclosed 107 zero-day vulnerabilities affecting elements of its mobile operating system and any system relying on the open source version of it, Android Open Source Project (AOSP).

The advisory, published on December 1, included patches for 51 flaws – 37 affecting the Android framework and 14 defects affecting the system – with the rest to be shared on December 5.

Out of the 51 patched flaws, three are of particular significance.

Two of them, tracked as CVE-2025-48633 and CVE-2025-48572, “may be under limited, targeted exploitation,” said Google.

Both are classified as information disclosure (ID) issues in the Android framework with high severity ratings. They both affect Android 13, 14, 15 and 16.

When exploited, CVE-2025-48633 allows unauthorized disclosure of information and CVE-2025-48572 enables attackers to gain elevated access on vulnerable devices.

Neither has been added to the US Cybersecurity and Infrastructure Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog at the time of writing.

The advisory also includes a critical security vulnerability in the Android Framework that could lead to remote denial of service with no additional execution privileges needed. This flaw is tracked as CVE-2025-48631.

The rest of the patches will be released on December 5.

These patches will account for 56 vulnerabilities affecting Android components in the kernel, or third-party components, like Arm, Imagination Technologies, MediaTek, Qualcomm and Unison.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-patches-android-0day/