English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

Google Releases December 2025 Android Security Patch: 107 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days

Forum topic · ✨步子哥 · 2025-12-04

Summary

Google has published its December 2025 Android Security Bulletin, fixing a total of 107 vulnerabilities across the Framework (35), System (25), Kernel (20), and third-party components (27). The release addresses 7 critical issues and 2 zero-day vulnerabilities that Google confirmed were under limited, targeted exploitation: CVE-2025-48633, an information disclosure flaw in the Android Framework, and CVE-2025-48572, a privilege escalation vulnerability with a CVSS score of 7.4 that could allow local apps to execute arbitrary code. CISA has added both to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to apply fixes by December 23, 2025. The patches affect Android 13, 14, 15, and 16, and users are advised to update to security patch level 2025-12-05 or later. Other risks include privilege escalation, information disclosure, and a remote denial-of-service issue (CVE-2025-48631). Users should install updates promptly, install apps only from official stores, review app permissions, and keep anti-malware solutions up to date.

Google has released its December 2025 Android Security Bulletin, addressing 107 vulnerabilities, including 2 zero-day flaws confirmed to be under active, targeted exploitation.

Key statistics

  • Total vulnerabilities fixed: 107
  • Critical severity: 7
  • Zero-days actively exploited: 2
  • Affected Android versions: Android 13, 14, 15, and 16
  • Fixes by component

    | Component | Number of fixes | | --- | --- | | Framework | 35 | | System | 25 | | Kernel | 20 | | Third-party components | 27 |

    The two zero-day vulnerabilities

    1. CVE-2025-48633 — An information disclosure vulnerability in the Android Framework component, rated high severity. It could lead to the leakage of sensitive information. 2. CVE-2025-48572 — A privilege escalation vulnerability with a CVSS score of 7.4/10, which could allow a local application to execute arbitrary code.

    Google confirmed that both vulnerabilities "may be under limited, targeted exploitation," and CISA has added them to its Known Exploited Vulnerabilities catalog. US federal agencies must apply the fixes by December 23, 2025.

    Affected versions

    The issues impact Android 13, Android 14, Android 15, and Android 16. All users on these versions should update to the 2025-12-05 or later security patch level as soon as possible.

    Potential risks

  • Privilege escalation: Attackers could gain elevated privileges on a device and perform unauthorized operations.
  • Information disclosure: Sensitive data, including personal information and credentials, may be accessed without authorization.
  • Denial of service: A specific vulnerability (CVE-2025-48631) could enable remote DoS attacks without requiring additional execution privileges.

Security recommendations

1. Update immediately: Check for and install the latest Android security update (2025-12-05 patch level or higher). 2. App sources: Only install apps from official app stores; avoid apps promoted via links in SMS, email, or messaging apps. 3. Permission review: Carefully check the permissions apps request, especially sensitive ones such as accessibility, SMS, or camera access. 4. Security software: Use an up-to-date anti-malware solution to protect against known threats.

For full details, see the official Android Security Bulletin.

Tags

#android#security-patch#google#zero-day#cve-2025-48633#cve-2025-48572#cisa#vulnerability

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/176415072