National Cyber Warfare Foundation (NCWF)

Google addressed two Android flaws actively exploited in targeted attacks


0 user ratings
2025-09-03 17:50:54
milo
Blue Team (CND) , Attacks
Google addressed 120 Android vulnerabilities in September 2025, including two flaws actively exploited in targeted attacks. Google has released security updates to address 120 Android vulnerabilities as part of Android Security Bulletin – September 2025. Two of these vulnerabilities have been exploited in targeted attacks. “There are indications that the following may be under limited, targeted […


Google addressed 120 Android vulnerabilities in September 2025, including two flaws actively exploited in targeted attacks.





Google has released security updates to address 120 Android vulnerabilities as part of Android Security Bulletin – September 2025. Two of these vulnerabilities have been exploited in targeted attacks.





“There are indications that the following may be under limited, targeted exploitation.






  • CVE-2025-38352 (CVSS score: 7.4) – A privilege escalation flaw in the Linux Kernel component




  • CVE-2025-48543 (CVSS score: N/A) – A privilege escalation flaw in the Android Runtime component





reads the advisory.





Google warned that the two flaws allow local privilege escalation without extra permissions or user interaction.





Benoît Sevens of Google’s Threat Analysis Group (TAG) discovered the flaw CVE-2025-38352, a circumstance that suggests that it may have been exploited by advanced threat actors in spyware attacks.





As usual, the tech giant did not disclose technical details on their exploitation.





Google released two Android security patch levels (2025-09-01 and 2025-09-05) to help partners address shared vulnerabilities quickly and urges using the latest patch.





The most severe of the issues addressed by the tech giant is a critical System flaw, tracked as CVE-2025-48539, that allows remote code execution without extra privileges or user interaction, posing a high-risk exploitation threat.





CVE-2025-48539 is a severe System RCE flaw exploitable by nearby attackers without user interaction, posing a high compromise risk.





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, Google Android)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/181871/security/google-addressed-two-android-flaws-actively-exploited-in-targeted-attacks.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.