ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google fixes Android vulnerabilities "under targeted exploitation" (CVE-2025-48633, CVE-2025-48572)

highVulnerability exploited in the wildimportance 60CVE-2025-48633CVE-2025-48572

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48572
+1 in the same advisory: …48633
Local Privilege Escalation in Android Framework Under Active Exploitation

CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%.

Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe.

7.8
group max
<1% KEV
  • Google Android (Framework component)
massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device)
Full article319 words · extracted from helpnetsecurity.com · click to collapse

Google has shipped patches for 51 Android vulnerabilities, including two high-severity flaws (CVE-2025-48633, CVE-2025-48572) that “may be under limited, targeted exploitation”.

CVE-2025-48633 CVE-2025-48572

According to the December Android security bulletin, both vulnerabilities affect the Android Framework, which is a collection of core software components, libraries, and APIs that developers use to build Android apps.

Their exact nature has yet to be revealed, but the bulletin notes that CVE-2025-48633 can be exploited by Android applications to access sensitive information, and CVE-2025-48572 may allow attackers to elevate privileges on vulnerable Android devices.

As per usual, details about the attacks are kept under wraps, but the wording seems to point to state-sponsored attackers and/or espionage via spyware.

The bulletin lists additional 56 flaws affecting Android’s kernel, and ARM, Imagination Technologies, MediaTek, Unisoc and Qualcomm components. Patches for those will be included in the December 5 “patch level” (2025-12-05).

(Google ships two security patch levels “so that Android partners have the flexibility to fix a subset of vulnerabilities that are similar across all Android devices more quickly.”)

The December 1 patches (2025-12-01) are available for Android 13, 14, 15, and 16.

Security updates for Android-based devices

Vendors of Android-powered devices usually get a month or so to develop security updates, so they may ship them around the same time Google publishes its monthly Android security bulletin.

Samsung has pushed out a maintenance release for major flagship models that includes patches from both Google and Samsung, including the one for CVE-2025-48633.

Motorola has likewise patched only CVE-2025-48633 this December.

Huawei, LGE, Nokia, Oppo, and others are expected to release patches soon.

Android users are advised to check for updates and implement them if they are available.

UPDATE (December 3, 2025, 09:30 a.m. ET):

CISA has added the two vulnerabilities to its Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/02/android-cve-2025-48633-cve-2025-48572/