Google has released the September 2025 security update for Android devices, addressing a total of 84 vulnerabilities, including two actively exploited flaws. The two flaws that were detected as exploited in zero-day attacks are CVE-2025-38352, an elevation of privilege in the Android kernel, and CVE-2025-48543, also an elevation of privilege problem in the Android Runtime component. Google noted in its bulletin that there are indications that those two flaws may be under limited, targeted exploitation, without sharing any more details. The CVE-2025-38352 flaw is a Linux kernel flaw first disclosed on July 22, 2025, fixed in kernel versions 6.12.35-1 and later. It was not previously marked as actively exploited. The flaw is a race condition in POSIX CPU timers, allowing task cleanup disruption and kernel destabilization, potentially leading to crashes, denial of service, and privilege escalation. CVE-2025-48543 impacts the Android Runtime, where Java/Kotlin apps and system services execute. It potentially allows a malicious app to bypass sandbox restrictions and access higher-level system capabilities. Apart from the two actively exploited flaws, Google's September 2025 update for Android also addresses four critical-severity problems. The first is CVE-2025-48539, a remote code execution (RCE) problem in Android's System component. It allows an attacker within physical or network proximity, such as Bluetooth or WiFi range, to execute arbitrary code on the device without any u...
Google fixes actively exploited Android flaws in September update
BleepingComputer
·Bill Toulas
·Published Sep 3, 2025
·Updated
Affected Software
2 affected components
Google Android
Linux Kernel=6.12.35-1
Frequently Asked Questions
1
What is the main topic of this article?
The article focuses on Google's September 2025 security update for Android, which addresses 84 vulnerabilities, including two that are actively exploited.
2
What security implications are discussed in the article?
The article highlights the presence of two zero-day vulnerabilities in Android that are actively being exploited, posing significant security risks.
3
Which versions of Android are affected by these vulnerabilities?
The vulnerabilities impact various Android devices that receive the September 2025 security update.
4
What specific vulnerabilities are mentioned in the article?
The article references two actively exploited flaws identified as CVE-2025-XXXX and CVE-2025-YYYY, although the specifics of these CVEs are not detailed.
5
What other software is mentioned as being affected alongside Google Android?
The Linux kernel, specifically version 6.12.35-1, is also mentioned as being affected by the vulnerabilities addressed in the update.