Android drops mega patch bomb - 120 fixes, two already exploited
ID: fed37fbc-5633-5223-82d8-f3b8a789ef94
STIX ID: report--fed37fbc-5633-5223-82d8-f3b8a789ef94
Feed Name: The Register (Security)
Android's September security bulletin delivers 120 patches — its largest monthly update of the year — including two high-severity local privilege escalation flaws (CVE-2025-38352 in the Linux kernel and CVE-2025-48543 in the Android runtime) which Google and Hong Kong CERT say show signs of limited, targeted exploitation; additional critical issues affect Qualcomm and Imagination GPUs. The report warns that while Pixel devices will be patched quickly, many other Android handsets could remain vulnerable due to delayed OEM rollouts, increasing exposure to potential surveillanceware-style attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
