Google addresses 34 high-severity vulnerabilities in June’s Android security update
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-21479 | Incorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates. Do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets. | 8.6 group max | <1% | KEV |
| masshundreds of millions of devices (estimated) | |
| CVE-2025-26443 | In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. NVD description · AI analysis pending | 7.3 | <1% |
| — |
Full article511 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The most serious flaw in the monthly security update affects the Android system and could be exploited to achieve local escalation of privilege, the company said.
Listen to this article
0:00
Learn more.
Google’s June security update for Android devices contains 34 vulnerabilities, all of which the company designates as high-severity defects. The company didn’t disclose any actively exploited vulnerabilities.
Attackers could exploit the most serious flaw — CVE-2025-26443 affecting the Android system — to achieve local escalation of privilege with no additional privileges required. Google said exploitation of the vulnerability requires user interaction.
Google’s security update includes one high-severity vulnerability in Android Runtime, 11 high-severity defects affecting the Android framework and four high-severity vulnerabilities affecting the Android system. The vulnerabilities, if exploited, could allow attackers to achieve escalation of privileges, remote code execution, denial of service and information disclosure.
The company did not address a trio of Qualcomm component zero-days — CVE-2025-21479, CVE-2025-21480 and CVE-2025-27038 — the chipmaker disclosed in a separate security bulletin Monday. Qualcomm said Google’s Threat Analysis Group determined the three memory-corruption flaws “may be under limited, targeted exploitation.”
The Cybersecurity and Infrastructure Security Agency added all three Qualcomm component vulnerabilities to the known exploited vulnerabilities catalog Tuesday.
The Android security update contains two patch levels — 2025-06-01 and 2025-06-05 — allowing Android partners to address a group of 16 common vulnerabilities on different devices.
The second patch includes fixes for two high-severity vulnerabilities affecting Arm components, seven defects in Imagination Technologies components and nine total vulnerabilities in Qualcomm components.
Third-party Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.
Google said source code patches for all 34 vulnerabilities addressed in this month’s security update will be released to the Android Open Source Project repository by Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-june-2025/