ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Google addresses 34 high-severity vulnerabilities in June’s Android security update

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-21479
+2 in the same advisory: …21480 …27038
Incorrect Authorization in Qualcomm GPU Firmware Across Multiple Chipsets

CVE-2025-21479 is an incorrect authorization flaw (CWE-863) in Qualcomm chipset firmware that allows unauthorized command execution in a GPU micronode, causing memory corruption when the GPU processes a specific sequence of commands. Because the CVSS vector is local (AV:L) with user interaction required, exploitation most plausibly involves a malicious local application or process driving the GPU through the vulnerable command sequence. An attacker who successfully triggers the flaw gains high-impact confidentiality, integrity, and availability effects with scope change, meaning the compromise can extend beyond the GPU component to the broader device. Affected products span Qualcomm AQT1000, FastConnect 6200/6700/6800/6900/7800, QCA6391, QCM4490, QCS4490, Snapdragon 855 (SD855), SM4635, and SM6250 firmware, i.e., chipsets used in Android smartphones and IoT/industrial devices. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-03, and news reports describe limited, targeted Android attacks exploiting Qualcomm GPU zero-days fixed in Google's 2025 Android security updates.

Do: Apply Qualcomm's fix by installing the Android security update from June 2025 or later (or the OEM/vendor firmware update for QCM4490, QCS4490, FastConnect, and other affected chipsets), checking your device's security patch level and chipset firmware against Qualcomm's bulletin, which lists the exact fixed versions. Organizations subject to BOD 22-01 must apply vendor mitigations per CISA's KEV required action or discontinue use of affected products; there is no known public PoC, but exploitation in targeted attacks is confirmed, so prioritize patching internet-facing and user-facing Android fleets.

8.6
group max
<1% KEV
  • Qualcomm AQT1000 firmware
  • Qualcomm FastConnect 6200 firmware
  • Qualcomm FastConnect 6700 firmware
  • +9 more
masshundreds of millions of devices (estimated)
CVE-2025-26443
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the

In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

NVD description · AI analysis pending
7.3<1%
  • google android
Full article511 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The most serious flaw in the monthly security update affects the Android system and could be exploited to achieve local escalation of privilege, the company said.

Listen to this article

0:00

Learn more.

(GABRIEL BOUYS/AFP via Getty Images)

Google’s June security update for Android devices contains 34 vulnerabilities, all of which the company designates as high-severity defects. The company didn’t disclose any actively exploited vulnerabilities.

Attackers could exploit the most serious flaw — CVE-2025-26443 affecting the Android system — to achieve local escalation of privilege with no additional privileges required. Google said exploitation of the vulnerability requires user interaction. 

Google’s security update includes one high-severity vulnerability in Android Runtime, 11 high-severity defects affecting the Android framework and four high-severity vulnerabilities affecting the Android system. The vulnerabilities, if exploited, could allow attackers to achieve escalation of privileges, remote code execution, denial of service and information disclosure.

The company did not address a trio of Qualcomm component zero-days — CVE-2025-21479, CVE-2025-21480 and CVE-2025-27038 — the chipmaker disclosed in a separate security bulletin Monday. Qualcomm said Google’s Threat Analysis Group determined the three memory-corruption flaws “may be under limited, targeted exploitation.” 

The Cybersecurity and Infrastructure Security Agency added all three Qualcomm component vulnerabilities to the known exploited vulnerabilities catalog Tuesday.

The Android security update contains two patch levels — 2025-06-01 and 2025-06-05 — allowing Android partners to address a group of 16 common vulnerabilities on different devices.

The second patch includes fixes for two high-severity vulnerabilities affecting Arm components, seven defects in Imagination Technologies components and nine total vulnerabilities in Qualcomm components.

Third-party Android device manufacturers release security patches on their own schedule after they’ve customized operating system updates for their specific hardware.

Google said source code patches for all 34 vulnerabilities addressed in this month’s security update will be released to the Android Open Source Project repository by Wednesday.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/android-security-update-june-2025/