Patch Tuesday is next week, but Android is ahead of the game, dropping its biggest patch bundle this year while attackers actively exploit two of the now-fixed flaws. This month, the world's most popular mobile operating system pushed out 120 patches, its biggest monthly dump this year. It's a far cry from July, when Android didn't issue a single patch as everything was apparently fine, but in September, two of the flaws may be under "limited, targeted exploitation." The two biggest concerns are CVE-2025-38352, a high-severity problem with the Linux kernel at the heart of the operating system, and CVE-2025-48543, a high-severity issue with Android's runtime environment hosting apps. An attacker can escalate local privileges with both flaws, without even requiring user interaction. Google declined to name who is exploiting the flaws or how, but the language suggests that a surveillanceware company is using them to break in. We asked noted flaw-finders Citizen Lab at the University of Toronto, but they say that they haven't detected anyone using the vulns. However, the Hong Kong computer emergency response team issued an alert and echoed Google's warning, noting there are signs of limited, targeted exploitation. "CVE-2025-38352 and CVE-2025-48543 are being scattered [sic] exploited," it warned. September's update also includes three critical vulnerabilities in Qualcomm's closed-source components. CVE-2025-21450 is a CVSS 9.1-rated vulnerability in its GPS control system, CVE-20...
Android drops mega patch bomb - 120 fixes, two already exploited
The Register
·Iain Thomson
·Published Sep 3, 2025
·Updated
Affected Software
2 affected components
Google Android
Linux Kernel