• News/
  • https://www.theregister.com/2025/12/02/android_0_days/

Two Android 0-day bugs patched, plus 105 more fixes

The Register
·
Jessica Lyons
·
Published Dec 2, 2025
·
Updated

Two high-severity Android bugs were exploited as zero-days before Google issued a fix, according to its December Android security bulletin. The two vulnerabilities are CVE-2025-48633, an information-disclosure flaw in Android's framework component, and CVE-2025-48572, an elevation-of-privilege bug also in the framework component. Both are ranked high severity, and according to Google, both "may be under limited, targeted exploitation." Both of these – plus an additional 105 security holes – all have patches, so it's a good idea to update your Android software ASAP. Google didn't provide any details about who is exploiting the vulnerabilities, nor to what end, but we know that commercial spyware and government-sponsored attackers like to exploit these types of mobile device zero-days for snooping purposes. On Tuesday, the US Cybersecurity and Infrastructure Security Agency added both CVE-2025-48633 and CVE-2025-48572 to its its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal agencies to patch by December 23 and “strongly” urging all organizations to do the same “to reduce their exposure to cyberattacks.” This latest zero-day follows an emergency patch that Google issued last month for a high-severity Chrome bug that attackers have already found and exploited in the wild. That vulnerability, tracked as CVE-2025-13223, is a type confusion flaw in the V8 JavaScript engine, and it marked the seventh Chrome zero-day this year. All have since been patched. Seven bug...

Read full article

Affected Software

1 affected component
Google Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the patching of two high-severity Android 0-day vulnerabilities along with 105 other fixes in Google's December security bulletin.

2

What security implications are discussed in the article?

The article highlights the risks of information disclosure and exploitation associated with the two newly patched Android vulnerabilities.

3

What are the CVE identifiers for the vulnerabilities mentioned?

The vulnerabilities are identified as CVE-2025-48633 and another unspecified flaw in the article.

4

Who issued the patch for the vulnerabilities?

The patch for the vulnerabilities was issued by Google.

5

Which software product is affected by these vulnerabilities?

The affected software product is Google Android.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203