Article Details
Scrape Timestamp (UTC): 2025-12-02 07:18:42.061
Source: https://thehackernews.com/2025/12/google-patches-107-android-flaws.html
Original Article Text
Click to Toggle View
Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild. Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild. The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison. The two high-severity shortcomings that have been exploited are listed below - As is customary, Google has not released any additional details about the nature of the attacks, exploiting them, if they have been chained together or used separately, and the scale of such efforts. It's not known who is behind the attacks. However, the tech giant acknowledged in its advisory that there are indications they "may be under limited, targeted exploitation." Also fixed by Google as part of the December 2025 updates is a critical vulnerability in the Framework component (CVE-2025-48631) that could result in remote denial-of-service (DoS) with no additional execution privileges needed. The security bulletin for December includes two patch levels, namely, 2025-12-01 and 2025-12-05, giving device manufacturers flexibility to address a portion of vulnerabilities that are similar across all Android devices more quickly. Users are recommended to update their devices to the latest patch level as soon as the patches are released. The development comes three months after the company shipped fixes to remediate two actively exploited flaws in the Linux Kernel (CVE-2025-38352, CVSS score: 7.4) and Android Runtime (CVE-2025-48543, CVSS score: 7.4) that could lead to local privilege escalation.
Daily Brief Summary
Google has issued a security update for Android, addressing 107 vulnerabilities, including two high-severity flaws currently being exploited in the wild.
The vulnerabilities span multiple components such as Framework, System, and Kernel, with contributions from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison.
Details on the nature of the attacks exploiting these vulnerabilities remain undisclosed, but Google notes potential limited, targeted exploitation.
A critical Framework vulnerability (CVE-2025-48631) could allow remote denial-of-service attacks without requiring additional execution privileges.
The update introduces two patch levels, 2025-12-01 and 2025-12-05, enabling manufacturers to expedite addressing universal vulnerabilities.
Users are urged to update their devices promptly to mitigate potential risks associated with these vulnerabilities.
This release follows Google's recent efforts to patch actively exploited flaws in the Linux Kernel and Android Runtime, highlighting ongoing security challenges.