• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-flaws-in-september-update/

Google fixes actively exploited Android flaws in September update

BleepingComputer
·
Bill Toulas
·
Published Sep 3, 2025
·
Updated

Google has released the September 2025 security update for Android devices, addressing a total of 84 vulnerabilities, including two actively exploited flaws. The two flaws that were detected as exploited in zero-day attacks are CVE-2025-38352, an elevation of privilege in the Android kernel, and CVE-2025-48543, also an elevation of privilege problem in the Android Runtime component. Google noted in its bulletin that there are indications that those two flaws may be under limited, targeted exploitation, without sharing any more details. The CVE-2025-38352 flaw is a Linux kernel flaw first disclosed on July 22, 2025, fixed in kernel versions 6.12.35-1 and later. It was not previously marked as actively exploited. The flaw is a race condition in POSIX CPU timers, allowing task cleanup disruption and kernel destabilization, potentially leading to crashes, denial of service, and privilege escalation. CVE-2025-48543 impacts the Android Runtime, where Java/Kotlin apps and system services execute. It potentially allows a malicious app to bypass sandbox restrictions and access higher-level system capabilities. Apart from the two actively exploited flaws, Google's September 2025 update for Android also addresses four critical-severity problems. The first is CVE-2025-48539, a remote code execution (RCE) problem in Android's System component. It allows an attacker within physical or network proximity, such as Bluetooth or WiFi range, to execute arbitrary code on the device without any u...

Read full article

Affected Software

2 affected components
Google Android
Linux Kernel=6.12.35-1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article focuses on Google's September 2025 security update for Android, which addresses 84 vulnerabilities, including two that are actively exploited.

2

What security implications are discussed in the article?

The article highlights the presence of two zero-day vulnerabilities in Android that are actively being exploited, posing significant security risks.

3

Which versions of Android are affected by these vulnerabilities?

The vulnerabilities impact various Android devices that receive the September 2025 security update.

4

What specific vulnerabilities are mentioned in the article?

The article references two actively exploited flaws identified as CVE-2025-XXXX and CVE-2025-YYYY, although the specifics of these CVEs are not detailed.

5

What other software is mentioned as being affected alongside Google Android?

The Linux kernel, specifically version 6.12.35-1, is also mentioned as being affected by the vulnerabilities addressed in the update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203