Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild
Google发布安卓系统月度安全更新,修复107个漏洞,包括两个已被利用的高危漏洞(信息泄露和权限提升)及一个可能导致远程拒绝服务攻击的关键漏洞。 2025-12-2 07:17:0 Author: thehackernews.com(查看原文) 阅读量:7 收藏

Mobile Security / Vulnerability

Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild.

The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison.

The two high-severity shortcomings that have been exploited are listed below -

  • CVE-2025-48633 - An information disclosure vulnerability in Framework
  • CVE-2025-48572 - An elevation of privilege vulnerability in Framework

As is customary, Google has not released any additional details about the nature of the attacks, exploiting them, if they have been chained together or used separately, and the scale of such efforts. It's not known who is behind the attacks.

Cybersecurity

However, the tech giant acknowledged in its advisory that there are indications they "may be under limited, targeted exploitation."

Also fixed by Google as part of the December 2025 updates is a critical vulnerability in the Framework component (CVE-2025-48631) that could result in remote denial-of-service (DoS) with no additional execution privileges needed.

The security bulletin for December includes two patch levels, namely, 2025-12-01 and 2025-12-05, giving device manufacturers flexibility to address a portion of vulnerabilities that are similar across all Android devices more quickly. Users are recommended to update their devices to the latest patch level as soon as the patches are released.

The development comes three months after the company shipped fixes to remediate two actively exploited flaws in the Linux Kernel (CVE-2025-38352, CVSS score: 7.4) and Android Runtime (CVE-2025-48543, CVSS score: 7.4) that could lead to local privilege escalation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2025/12/google-patches-107-android-flaws.html
如有侵权请联系:admin#unsafe.sh