2 Android Zero-Day Bugs Under Active Exploit
ID: 19585392-c608-5df9-a2b0-456767f752c5
STIX ID: report--19585392-c608-5df9-a2b0-456767f752c5
Feed Name: Dark Reading
Date Published: 2025-04-08
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Google released patches for 62 Android vulnerabilities, including two actively exploited zero-days in Linux kernel USB components: CVE-2024-53197 (privilege escalation) — linked to a Cellebrite exploit chain used to unlock a protester's device and attempt spyware installation — and CVE-2024-53150 (out-of-bounds information disclosure, CVSS 7.1). Fixes are available for Android 13.14 and 15, and users should update to patch level 2025-04-05 or later when their device vendor rolls out the updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
