Two high-severity Android bugs were exploited as zero-days before Google issued a fix, according to its December Android security bulletin. The two vulnerabilities are CVE-2025-48633, an information-disclosure flaw in Android's framework component, and CVE-2025-48572, an elevation-of-privilege bug also in the framework component. Both are ranked high severity, and according to Google, both "may be under limited, targeted exploitation." Both of these – plus an additional 105 security holes – all have patches, so it's a good idea to update your Android software ASAP. Google didn't provide any details about who is exploiting the vulnerabilities, nor to what end, but we know that commercial spyware and government-sponsored attackers like to exploit these types of mobile device zero-days for snooping purposes. On Tuesday, the US Cybersecurity and Infrastructure Security Agency added both CVE-2025-48633 and CVE-2025-48572 to its its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal agencies to patch by December 23 and “strongly” urging all organizations to do the same “to reduce their exposure to cyberattacks.” This latest zero-day follows an emergency patch that Google issued last month for a high-severity Chrome bug that attackers have already found and exploited in the wild. That vulnerability, tracked as CVE-2025-13223, is a type confusion flaw in the V8 JavaScript engine, and it marked the seventh Chrome zero-day this year. All have since been patched. Seven bug...
Two Android 0-day bugs patched, plus 105 more fixes
The Register
·Jessica Lyons
·Published Dec 2, 2025
·Updated
Affected Software
1 affected component
Google Android
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the patching of two high-severity Android 0-day vulnerabilities along with 105 other fixes in Google's December security bulletin.
2
What security implications are discussed in the article?
The article highlights the risks of information disclosure and exploitation associated with the two newly patched Android vulnerabilities.
3
What are the CVE identifiers for the vulnerabilities mentioned?
The vulnerabilities are identified as CVE-2025-48633 and another unspecified flaw in the article.
4
Who issued the patch for the vulnerabilities?
The patch for the vulnerabilities was issued by Google.
5
Which software product is affected by these vulnerabilities?
The affected software product is Google Android.