Friday, September 11, 2026

Android Issues Security Update to Patch Actively Exploited 0-Day Flaws

Google has released a critical Android Security Bulletin for September 2025, addressing multiple high-severity vulnerabilities that are currently being actively exploited in the wild.

The security patch level 2025-09-05 or later is required to protect Android devices from these serious threats.

The security bulletin reveals that two CVEs are under limited, targeted exploitation, making this update particularly urgent for Android users worldwide.

The most severe vulnerability affects the System component and could enable remote code execution without requiring any additional privileges or user interaction.

Critical Vulnerabilities Under Active Exploitation

According to Google’s security assessment, the vulnerability’s severity rating assumes that platform and service mitigations are disabled for development purposes or have been successfully bypassed by attackers. This indicates the potential for serious compromise if exploited successfully.

The security update addresses vulnerabilities across multiple Android components, with particular focus on the Android Runtime and System components.

CVEReferenceTypeSeverity
CVE-2025-38352A-425282960EoP (Elevation of Privilege)High
CVE-2025-48543A-421834866EoP (Elevation of Privilege)High

Both actively exploited vulnerabilities are classified as Elevation of Privilege (EoP) flaws with High severity ratings.

CVE-2025-38352 affects the Android Runtime component and has been linked to upstream kernel issues.

Meanwhile, CVE-2025-48543 impacts Android versions 13, 14, 15, and 16, demonstrating the widespread nature of these security concerns across the Android ecosystem.

Android partners were notified of these vulnerabilities at least one month before public disclosure, following Google’s responsible disclosure practices.

Source code patches will be released to the Android Open Source Project (AOSP) repository within 48 hours of the bulletin publication.

Users should immediately check their device’s security patch level and install available updates.

The security team strongly encourages all users to update to the latest version of Android where possible, as newer versions include enhanced security protections that make exploitation significantly more difficult.

This security bulletin represents a critical moment for Android security, particularly given the active exploitation of these vulnerabilities.

The rapid response from Google and the Android security team demonstrates the ongoing commitment to protecting the billions of Android devices worldwide from sophisticated cyber threats.

The coordinated disclosure and patching process, combined with enhanced monitoring through Google Play Protect, showcases the multi-layered approach necessary to maintain security in today’s complex mobile threat landscape.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News