• News/
  • https://www.bleepingcomputer.com/news/security/google-fixes-two-android-zero-days-exploited-in-attacks-107-flaws/

Google fixes two Android zero days exploited in attacks, 107 flaws

BleepingComputer
·
Bill Toulas
·
Published Dec 2, 2025
·
Updated

Google has released the December 2025 Android security bulletin, addressing 107 vulnerabilities, including two flaws actively exploited in targeted attacks. The two high-severity vulnerabilities are tracked as CVE-2025-48633 and CVE-2025-48572. They are information disclosure and elevation-of-privilege issues, respectively, affecting Android versions 13 through 16. "There are indications that the following may be under limited, targeted exploitation," mentions the December Android bulletin. While Google has not shared any technical or exploitation details about the flaws, similar flaws in the past were used for targeted exploitation by commercial spyware or nation-state operations targeting a small number of high-interest individuals. Ranked by severity, the most critical vulnerability fixed this month is CVE-2025-48631, a denial-of-service (DoS) flaw in the Android Framework. This month's updates address a total of 51 flaws on Android Framework and System components, covered by the 2025-12-01 Patch Level, and another 56 bugs in the Kernel and third-party closed-source components, covered by the 2025-12-05 Patch Level. In what concerns the latter, there are four critical-severity fixes for elevation-of-privilege flaws in the Kernel's Pkvm and UOMMU subcomponents, and two critical fixes for Qualcomm-powered devices (CVE-2025-47319 and CVE-2025-47372). More information about closed-source fixes can be found in Qualcomm's and MediaTek's bulletins for the December 2025 security ...

Read full article

Affected Software

4 affected components
Google Android=13
Google Android=14
Google Android=15
Google Android=16
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What major vulnerabilities did Google fix in the December 2025 Android security update?

Google addressed two high-severity zero-day vulnerabilities, CVE-2025-48633 and CVE-2025-48572.

2

What types of vulnerabilities are CVE-2025-48633 and CVE-2025-48572?

They are classified as information disclosure and elevation-of-privilege vulnerabilities.

3

How many vulnerabilities in total were addressed in the December 2025 Android security bulletin?

The bulletin addressed a total of 107 vulnerabilities.

4

Have the fixed vulnerabilities been exploited in the wild?

Yes, the two zero-day vulnerabilities were actively exploited in targeted attacks.

5

Which platform is affected by these vulnerabilities?

The vulnerabilities affect the Google Android operating system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203