Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild.
A total of 107 security vulnerabilities from various components—including Framework, System, and Kernel—as well as those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison are fixed by the patch.
The following is a list of the two high-severity flaws that have been exploited:
- CVE-2025-48633 – An information disclosure vulnerability in Framework
- CVE-2025-48572 – An elevation of privilege vulnerability in Framework
As is customary, Google has not revealed any additional details about the nature of the attacks, exploiting them, if they have been chained together or utilized individually, and the extent of such operations. Who is responsible for the attacks is unknown read more about Google Patches 107 Android Flaws Including Two Framework Bugs Exploited in the Wild.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
