Google fixes two Android zero days exploited in attacks, 107 flaws
ID: 3d95b08c-3ae7-5398-be82-04dc15ab156c
STIX ID: report--3d95b08c-3ae7-5398-be82-04dc15ab156c
Feed Name: Bleeping Computer
Google published the December 2025 Android security bulletin addressing 107 vulnerabilities, including two flaws reported as possibly under limited targeted exploitation (CVE-2025-48633 — information disclosure; CVE-2025-48572 — elevation of privilege) affecting Android 13–16. The update also includes critical kernel elevation-of-privilege fixes and vendor-specific patches (Qualcomm, MediaTek, Samsung); users and administrators are urged to apply the December patch levels and keep Play Protect and system components updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
