{"id":297840,"date":"2025-12-04T02:46:23","date_gmt":"2025-12-04T02:46:23","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/297840\/"},"modified":"2025-12-04T02:46:23","modified_gmt":"2025-12-04T02:46:23","slug":"107-android-flaws-just-got-patched-by-google-heres-how-to-make-sure-youre-up-to-date","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/297840\/","title":{"rendered":"107 Android flaws just got patched by Google &#8211; here&#8217;s how to make sure you&#8217;re up to date"},"content":{"rendered":"<p>Google patched 100+ Android flaws across System, Kernel, and Framework componentsTwo zero-days (CVE-2025-48633, CVE-2025-48572) exploited in spyware and surveillance campaignsCritical DoS bug (CVE-2025-48631) also fixed; users urged to update immediately<\/p>\n<p id=\"16f6c5d2-c5b0-434a-9b68-df7716f5ab83\">Earlier this week, <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/tag\/google\" data-auto-tag-linker=\"true\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/tag\/google\" rel=\"nofollow noopener\" target=\"_blank\">Google<\/a> released a new security update for the <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/best\/best-android-phones\" target=\"_blank\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/best\/best-android-phones\" rel=\"nofollow noopener\">Android<\/a> ecosystem, patching more than 100 different security flaws.<\/p>\n<p>These bugs were found in various components such as System, Kernel, and Framework, and affected different manufacturers including <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/tag\/arm\" data-auto-tag-linker=\"true\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/tag\/arm\" rel=\"nofollow noopener\" target=\"_blank\">Arm<\/a>, MediaTek, and Qualcomm.<\/p>\n<p><a id=\"elk-seasonal\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p id=\"16f6c5d2-c5b0-434a-9b68-df7716f5ab83-2\">Among them are two high-severity vulnerabilities in Framework that are apparently being abused in the wild. They are tracked as CVE.2025-48633, and CVE-2025-48572, and are described as an information disclosure flaw and an elevation of privilege flaw.<\/p>\n<p>Best picks for you<\/p>\n<p><a id=\"elk-3aa054fe-d16c-436c-8678-6e79640e6306\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><a id=\"elk-acd0b5d3-2f21-45d8-b5c7-1902cca12dcd\" class=\"paywall\" aria-hidden=\"true\" data-url=\"\" href=\"\" target=\"_blank\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\"\/><\/p>\n<p id=\"465588b3-e7c6-4a91-806e-e1ca852527cb\">Google did not share many details about the bugs, other than the fact that they affect Android versions 13, 14, 15, 16, and they \u201cmay be under limited, targeted exploitation\u201d. However, according to <a data-analytics-id=\"inline-link\" href=\"https:\/\/cyberinsider.com\/google-fixes-two-actively-exploited-android-zero-days-in-december-2025-security-update\/\" target=\"_blank\" data-url=\"https:\/\/cyberinsider.com\/google-fixes-two-actively-exploited-android-zero-days-in-december-2025-security-update\/\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">CyberInsider<\/a>, this is standard Google phrasing for \u201czero-days leveraged in spyware operations or state-sponsored surveillance campaigns.\u201d<\/p>\n<p>The same publication also says that similar zero-days have been exploited in the past by commercial <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.techradar.com\/best\/best-malware-removal\" target=\"_blank\" data-mrf-recirculation=\"inline-link\" data-before-rewrite-localise=\"https:\/\/www.techradar.com\/best\/best-malware-removal\" rel=\"nofollow noopener\">spyware<\/a> vendors such as NSO Group, Candiru, and Intellexa.<\/p>\n<p>\u201cElevation of privilege (EoP) vulnerabilities, like CVE-2025-48572, are particularly useful in these attacks to gain deeper access after an initial foothold, while information disclosure flaws, such as CVE-2025-48633, are often used to leak sensitive system memory or defeat sandboxing protections,\u201d it claims.<\/p>\n<p>While these two are important, they are not the only dangerous flaws on the list. Google also addressed a critical vulnerability in Framework, tracked as CVE-2025-48631 which, if abused, can result in remote denial-of-service (DoS). This bug does not require additional execution privileges to be exploited.<\/p>\n<p class=\"newsletter-form__strapline\">Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!<\/p>\n<p>The fix is split in two levels (2025-12-01 and 2025-12-05), allowing device manufacturers to address parts of the flaws, and thus move faster. If you are an Android user, and the device prompted you to install the update, make sure to do so as soon as possible.<\/p>\n<p>Earlier this year, Google fixed two bugs in the Linux Kernel that were also exploited in the wild &#8211; CVE-2025-38352, and CVE-2025-48543.<\/p>\n<p>Via <a data-analytics-id=\"inline-link\" href=\"https:\/\/thehackernews.com\/2025\/12\/google-patches-107-android-flaws.html\" target=\"_blank\" data-url=\"https:\/\/thehackernews.com\/2025\/12\/google-patches-107-android-flaws.html\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">The Hacker News<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/HpHXmtXFPnuzaQ8m9xNW8j.png\" alt=\"Best antivirus software header\"   class=\"person__avatar image-wrapped__image image__image\" loading=\"lazy\" data-normal=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/HpHXmtXFPnuzaQ8m9xNW8j.png\" data-original-mos=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/HpHXmtXFPnuzaQ8m9xNW8j.png\" data-pin-media=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/HpHXmtXFPnuzaQ8m9xNW8j.png\" data-pin-nopin=\"true\" data-slice-image=\"true\"\/><\/p>\n<p>The best antivirus for all budgets<\/p>\n<p>Our top picks, based on real-world testing and comparisons<\/p>\n<p id=\"cdd8e80c-0eee-49ee-a436-55c20a26cf98\"><a data-analytics-id=\"inline-link\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" target=\"_blank\" data-url=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEWFJsWTJoeVlXUmhjaTVqYjIwb0FBUAE?hl=en-GB&amp;gl=GB&amp;ceid=GB%3Aen\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">Follow TechRadar on Google News<\/a> and <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" target=\"_blank\" data-url=\"https:\/\/www.google.com\/preferences\/source?q=techradar.com\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">add us as a preferred source<\/a> to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!<\/p>\n<p>And of course you can also <a data-analytics-id=\"inline-link\" href=\"https:\/\/www.tiktok.com\/@techradar\" target=\"_blank\" data-url=\"https:\/\/www.tiktok.com\/@techradar\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">follow TechRadar on TikTok<\/a> for news, reviews, unboxings in video form, and get regular updates from us on <a data-analytics-id=\"inline-link\" href=\"https:\/\/whatsapp.com\/channel\/0029Va6HybZ9RZAY7pIUK12h\" target=\"_blank\" data-url=\"https:\/\/whatsapp.com\/channel\/0029Va6HybZ9RZAY7pIUK12h\" referrerpolicy=\"no-referrer-when-downgrade\" data-hl-processed=\"none\" data-mrf-recirculation=\"inline-link\" rel=\"nofollow noopener\">WhatsApp<\/a> too.<\/p>\n<p><script async src=\"\/\/www.tiktok.com\/embed.js\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Google patched 100+ Android flaws across System, Kernel, and Framework componentsTwo zero-days (CVE-2025-48633, CVE-2025-48572) exploited in spyware and&hellip;\n","protected":false},"author":2,"featured_media":297841,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[2306,86,56,54,55],"class_list":{"0":"post-297840","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-mobile","9":"tag-technology","10":"tag-uk","11":"tag-united-kingdom","12":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/297840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=297840"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/297840\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/297841"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=297840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=297840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=297840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}