logo

Google patches 107 Android flaws, including two being actively exploited

ID: 3c0a711f-24e4-5572-bf23-764f95b4bbc9

STIX ID: report--3c0a711f-24e4-5572-bf23-764f95b4bbc9

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-04-28

...
...

Malwarebytes highlights Google’s December 2025 Android Security Bulletin which patches 107 vulnerabilities and calls out two framework-level flaws under limited, targeted active exploitation (CVE-2025-48633 — likely information disclosure — and CVE-2025-48572 — CVSS 7.4, allows local arbitrary code execution). Users are advised to install updates (patch level 2025-12-05 or later), avoid installing untrusted apps, scrutinize permissions, and use up-to-date mobile security software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.