CVE-2025-48633 and CVE-2025-48572: Android Framework Information Disclosure and Privilege Escalation Vulnerabilities Exploited in the Wild
ID: 296b1426-1fc2-51d0-9a6d-4efa2bfffbc8
STIX ID: report--296b1426-1fc2-51d0-9a6d-4efa2bfffbc8
Feed Name: SOC Prime Blog
Threat Score
The report summarizes two actively exploited Android Framework flaws — CVE-2025-48633 (information disclosure) and CVE-2025-48572 (privilege escalation) — that Google patched in its December 2025 Android Security Bulletin and which CISA added to the Known Exploited Vulnerabilities catalog, urging prompt remediation; the article also highlights rising CVE volumes and recommends updating devices and applying mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
