Google Fixes Actively Exploited Android System Flaw in May 2025 Security Update
Google发布五月安全更新修复46个Android漏洞,其中最严重的是 CVE-2025-27363(CVSS 8.1),可导致本地代码执行无需额外权限,源于FreeType字体库并已被野外利用。该更新还修复了其他系统和框架模块中的多个高危漏洞,建议用户及时升级以增强安全性。 2025-5-6 05:46:0 Author: thehackernews.com(查看原文) 阅读量:12 收藏

Vulnerability / Mobile Security

Android System Flaw in May 2025 Security Update

Google has released its monthly security updates for Android with fixes for 46 security flaws, including one vulnerability that it said has been exploited in the wild.

The vulnerability in question is CVE-2025-27363 (CVSS score: 8.1), a high-severity flaw in the System component that could lead to local code execution without requiring any additional execution privileges.

"The most severe of these issues is a high security vulnerability in the System component that could lead to local code execution with no additional execution privileges needed," Google said in a Monday advisory. "User interaction is not needed for exploitation."

It's worth noting that CVE-2025-27363 is rooted in the FreeType open-source font rendering library. It was first disclosed by Facebook in March 2025 as having been exploited in the wild.

Cybersecurity

The shortcoming has been described as an out-of-bounds write flaw that could result in code execution when parsing TrueType GX and variable font files. The issue has been remediated in FreeType versions higher than 2.13.0.

"There are indications that CVE-2025-27363 may be under limited, targeted exploitation," Google acknowledged in its security bulletin. The exact specifics of the attacks are presently unknown.

Google's May update also resolves eight other flaws in the Android System and 15 flaws in the Framework module that could be abused to facilitate privilege escalation, information disclosure and denial-of-service.

"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform," the company said. "We encourage all users to update to the latest version of Android where possible."

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/05/google-fixes-actively-exploited-android.html
如有侵权请联系:admin#unsafe.sh