Article Details

Scrape Timestamp (UTC): 2025-09-03 11:09:07.274

Source: https://thehackernews.com/2025/09/android-security-alert-google-patches.html

Original Article Text

Click to Toggle View

Android Security Alert: Google Patches 120 Flaws, Including Two Zero-Days Under Attack. Google has shipped security updates to address 120 security flaws in its Android operating system as part of its monthly fixes for September 2025, including two issues that it said have been exploited in targeted attacks. The vulnerabilities are listed below - Google said both vulnerabilities could lead to local escalation of privilege with no additional execution privileges needed. It also noted that no user interaction is required for exploitation. The tech giant did not reveal how the issues have been weaponized in real-world attacks, but acknowledged there are indications of "limited, targeted exploitation." Also patched by Google are several remote code execution, privilege escalation, information disclosure, and denial-of-service vulnerabilities impacting Framework and System components. Google has released two security patch levels, 2025-09-01 and 2025-09-05, so as to give flexibility to Android partners to address a portion of vulnerabilities that are similar across all Android devices more quickly. "Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level," Google said. Last month, the tech giant Google released security updates to resolve two Qualcomm vulnerabilities -- CVE-2025-21479 (CVSS score: 8.6) and CVE-2025-27038 (CVSS score: 7.5) -- that were flagged by the chipmaker as actively exploited in the wild.

Daily Brief Summary

VULNERABILITIES // Google Addresses 120 Android Flaws, Including Two Active Zero-Days

Google released security updates for Android, addressing 120 vulnerabilities, including two zero-days actively exploited in targeted attacks, as part of its September 2025 patch cycle.

The zero-day vulnerabilities allow local escalation of privilege without requiring user interaction, posing significant risks to affected devices.

Additional patched issues include remote code execution, privilege escalation, information disclosure, and denial-of-service vulnerabilities impacting Framework and System components.

Google introduced two security patch levels, 2025-09-01 and 2025-09-05, to enable Android partners to address vulnerabilities more efficiently across devices.

Android partners are urged to implement all fixes from the bulletin and adopt the latest security patch levels to enhance device security.

Previous updates addressed two Qualcomm vulnerabilities actively exploited, indicating an ongoing focus on mitigating high-risk threats in the Android ecosystem.

The proactive patching strategy aims to safeguard users against potential exploitation, emphasizing the importance of timely updates in maintaining security.