{"id":168742,"date":"2025-12-05T01:46:23","date_gmt":"2025-12-05T01:46:23","guid":{"rendered":"https:\/\/www.newsbeep.com\/il\/168742\/"},"modified":"2025-12-05T01:46:23","modified_gmt":"2025-12-05T01:46:23","slug":"google-just-fixed-107-security-flaws-including-two-zero-days-update-your-android-phone-right-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/il\/168742\/","title":{"rendered":"Google just fixed 107 security flaws including two zero-days \u2014 update your Android phone right now"},"content":{"rendered":"<p id=\"73f3438d-a551-4859-85b9-a9d4caa35fd1\">This week Google issued fixes for 107 total security vulnerabilities, including two <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/phones\/android-phones\/google-just-fixed-46-security-flaws-including-an-actively-exploited-zero-day-update-your-android-phone-now\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/phones\/android-phones\/google-just-fixed-46-security-flaws-including-an-actively-exploited-zero-day-update-your-android-phone-now\" rel=\"nofollow noopener\" target=\"_blank\">zero-day flaws<\/a>, with the release of its <a data-analytics-id=\"inline-link\" href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-12-01\" target=\"_blank\" data-url=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2025-12-01\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Android Security Bulletin December 2025<\/a>. The two high severity bugs, which have been actively exploited in the wild, are CVE-2025-48633, which is an information disclosure bug, and CVE-2025-48572, which is an elevation of privilege issue. Another critical bug that was fixed this month is CVE-2025-48631 which is a DoS (denial-of-service) flaw in the Android Framework.<\/p>\n<p>The two highlighted vulnerabilities affect Android versions 13 through 16, and while Google in typical fashion has not shared details about any related technical or exploitation issues, it is understood that flaws like this have previously been used by <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/computing\/malware-adware\/samsung-phones-infected-with-landfall-spyware-through-whatsapp-images-what-you-need-to-know\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/computing\/malware-adware\/samsung-phones-infected-with-landfall-spyware-through-whatsapp-images-what-you-need-to-know\" rel=\"nofollow noopener\" target=\"_blank\">commercial spyware<\/a> for targeted exploitation and focus on high-value individuals. December\u2019s updates include 51 flaws addressed in the Android Framework and System components, and 56 bugs in the Kernel and third-party components; there are also four critical severity fixes for <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/computing\/online-security\/google-just-fixed-84-android-security-flaws-including-two-actively-exploited-zero-days-update-your-phone-right-now\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/computing\/online-security\/google-just-fixed-84-android-security-flaws-including-two-actively-exploited-zero-days-update-your-phone-right-now\" rel=\"nofollow noopener\" target=\"_blank\">elevation of privilege flaws<\/a>.<\/p>\n<p><a id=\"elk-seasonal\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p id=\"73f3438d-a551-4859-85b9-a9d4caa35fd1-2\" class=\"paywall\" aria-hidden=\"true\">Devices on Android 10 and later may also receive some critical fixes over Google Play System updates. Likewise, Samsung published its <a data-analytics-id=\"inline-link\" href=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" target=\"_blank\" data-url=\"https:\/\/security.samsungmobile.com\/securityUpdate.smsb\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">own security bulletin<\/a> which included the Google fixes from the update as well as its own patches.<\/p>\n<p>You may like<\/p>\n<p><a id=\"elk-b4cade13-7ce4-4d49-9c08-20899e592e0c\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/>How to keep your Android device protected<\/p>\n<p class=\"vanilla-image-block\" style=\"padding-top:56.26%;\">\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/12\/MRUEsvBrdDnwpsDgw3GGzh.jpg\" alt=\"A hand holding a phone securely logging in\"   loading=\"lazy\" data-new-v2-image=\"true\" data-original-mos=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/12\/MRUEsvBrdDnwpsDgw3GGzh.jpg\" data-pin-media=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/12\/MRUEsvBrdDnwpsDgw3GGzh.jpg\"\/>\n<\/p>\n<p>(Image credit: Google)<\/p>\n<p id=\"5f629b8d-7115-43e4-9d72-be769be1eca9\">Zero-day flaws like this are exactly the reason we encourage users to keep their operating systems and devices up-to-date. Taking advantage of <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/reviews\/google-play-protect\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/reviews\/google-play-protect\" rel=\"nofollow noopener\" target=\"_blank\">Google Play Protect<\/a> is a good to way to make sure your Android device can detect and block known malware and malicious apps, so ensure that this free, built-in security app is enabled and that your phone or tablet is up to date. Additionally, if you&#8217;re using an older smartphone, you should absolutely consider switching to a newer device to ensure that you&#8217;re able to get the most recent updates and support.<\/p>\n<p>For an additional layer of security, you can use one of the<a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/best-picks\/best-android-antivirus\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/best-picks\/best-android-antivirus\" rel=\"nofollow noopener\" target=\"_blank\"> best Android antivirus apps<\/a> alongside Google Play Protect as they can scan your phone for malware, alert you regarding apps that could be a security risk and protect you from<a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/reference\/what-are-phishing-scams\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/reference\/what-are-phishing-scams\" rel=\"nofollow noopener\" target=\"_blank\"> phishing attempts<\/a>.<\/p>\n<p>Although such a high number of vulnerabilities getting patched might raise concerns about Android overall, this is actually a good thing. Just like Microsoft does each month with its <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tomsguide.com\/news\/urgent-windows-update-patches-over-100-flaws-update-your-pc-now\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.tomsguide.com\/news\/urgent-windows-update-patches-over-100-flaws-update-your-pc-now\" rel=\"nofollow noopener\" target=\"_blank\">Patch Tuesday<\/a> updates, Google releases its Android security patches every month too. However, it&#8217;s up to you to install them and if you want the latest security patches as soon as they become available, you&#8217;re going to want to switch to one of the search giant&#8217;s own Google Pixel phones.<\/p>\n<p><a href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJ2YlhObmRXbGtaUzVqYjIwb0FBUAE\" rel=\"nofollow noopener\" id=\"0c62b114-ec5a-4b7c-946f-f1a77fb6e4a8\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJ2YlhObmRXbGtaUzVqYjIwb0FBUAE\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"><\/p>\n<p class=\"vanilla-image-block\" style=\"padding-top:31.51%;\">\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/11\/r3t8zZ5ve4GewFTeoCM3R6.jpg\" alt=\"Google News\"   loading=\"lazy\" data-new-v2-image=\"true\" data-original-mos=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/11\/r3t8zZ5ve4GewFTeoCM3R6.jpg\" data-pin-media=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/11\/r3t8zZ5ve4GewFTeoCM3R6.jpg\" class=\"pull-right\"\/>\n<\/p>\n<p><\/a><\/p>\n<p id=\"f2ff84df-f5f3-4695-88ba-d517e18eb889\">Follow <a data-analytics-id=\"inline-link\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJ2YlhObmRXbGtaUzVqYjIwb0FBUAE\" target=\"_blank\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJ2YlhObmRXbGtaUzVqYjIwb0FBUAE\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Tom&#8217;s Guide on Google News<\/a> and <a data-analytics-id=\"inline-link\" href=\"https:\/\/google.com\/preferences\/source?q=tomsguide.com\" target=\"_blank\" data-url=\"https:\/\/google.com\/preferences\/source?q=tomsguide.com\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">add us as a preferred source<\/a> to get our up-to-date news, analysis, and reviews in your feeds. <\/p>\n<p class=\"newsletter-form__strapline\">Get instant access to breaking news, the hottest reviews, great deals and helpful tips.<\/p>\n<p><a id=\"elk-more-from-tom-s-guide\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/>More from Tom&#8217;s Guide<a id=\"elk-fb4fb967-aac2-4e0f-accc-2aa6c9bc00cf\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p>Today&#8217;s best Bitdefender Mobile Security deals<\/p>\n<p><a data-google-interstitial=\"false\" aria-label=\"View Bitdefender Mobile Security on Bitdefender\" href=\"https:\/\/bitdefender.evyy.net\/c\/221109\/278689\/4466?subId1=tomsguide-us-7173484029805358413&amp;sharedId=hawk&amp;u=https%3A%2F%2Fwww.bitdefender.com%2Fsolutions%2Fmobile-security-android.html\" referrerpolicy=\"no-referrer-when-downgrade\" class=\"hawk-affiliate-link-container\" data-product-key=\"47476-475748210\" data-url=\"https:\/\/bitdefender.evyy.net\/c\/221109\/278689\/4466?subId1=tomsguide-us-7173484029805358413&amp;sharedId=hawk&amp;u=https%3A%2F%2Fwww.bitdefender.com%2Fsolutions%2Fmobile-security-android.html\" data-model-id=\"721346\" data-match-id=\"359352\" data-product-type=\"2500\" data-link-merchant=\"Bitdefender\" data-merchant-id=\"13942\" data-merchant-name=\"Bitdefender\" data-merchant-url=\"http:\/\/www.bitdefender.com\" rel=\"sponsored noopener nofollow\" target=\"_blank\" role=\"link\" tabindex=\"0\"><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/il\/wp-content\/uploads\/2025\/11\/bitdefender-15180017452308-100-80.png.webp.webp\" alt=\"Bitdefender\" title=\"Bitdefender\" class=\"hawk-lazy-image-logo-image\" draggable=\"false\" loading=\"lazy\" width=\"80\" height=\"40\"\/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"This week Google issued fixes for 107 total security vulnerabilities, including two zero-day flaws, with the release of&hellip;\n","protected":false},"author":2,"featured_media":168743,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[85,46,321,125],"class_list":{"0":"post-168742","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-il","9":"tag-israel","10":"tag-mobile","11":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/168742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/comments?post=168742"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/posts\/168742\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media\/168743"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/media?parent=168742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/categories?post=168742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/il\/wp-json\/wp\/v2\/tags?post=168742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}