logo

CVE-2025-48593: Critical Zero-Click Vulnerability in Android Enables Remote Code Execution

ID: 2e0597d2-bc99-5f76-a55d-e83b31db98fc

STIX ID: report--2e0597d2-bc99-5f76-a55d-e83b31db98fc

Feed Name: SOC Prime Blog

Threat Score
80/100

Date Published: 2025-11-05

Date Updated: 2026-04-30

Author: Veronika Telychko

...
...

Google's November 2025 Android Security Bulletin discloses CVE-2025-48593, a critical zero-click remote code execution vulnerability in the Android System affecting Android 13–16 that can allow remote attackers to run arbitrary code without user interaction; users should install security patches (2025-11-01 or later) immediately, and AOSP source fixes are expected within 48 hours. The bulletin also notes a separate high-severity elevation-of-privilege flaw (CVE-2025-48581) affecting Android 16, and the report highlights SOC Prime detection and mitigation tooling to help defenders anticipate and respond to these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.