Google fixes one actively exploited Android zero-day, 124 flaws
Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks and improving overall Android security, particularly for devices running Android 14 or later. Google continues to refine its vulnerability response program, offering substantial rewards for critical exploit reports.
Google’s latest security patch release tackles a concerning trend of actively exploited vulnerabilities within the Android ecosystem. The core issue, CVE-2025-48595, is a high-severity Android Framework vulnerability that allows for code execution and privilege escalation on devices running Android 14 or later. Google’s security bulletin indicates that this vulnerability is being targeted in limited, ongoing attacks, suggesting a sophisticated threat actor is actively seeking to exploit it. The update also includes fixes for 18 critical vulnerabilities across various Android components, including System, Framework, and Qualcomm closed-source components, aiming to prevent denial-of-service conditions and privilege escalation.
While Google hasn't disclosed specific details about the attackers or the targets of these attacks, the vulnerability's history mirrors past exploitation by commercial spyware and nation-state actors targeting high-value individuals. Google’s ongoing efforts to improve Android security are bolstered by its revamped vulnerability rewards program, offering substantial bounties – up to $1.5 million – for critical exploits, incentivizing researchers and security professionals to identify and report vulnerabilities. This program also reflects a shift in focus towards more complex and challenging vulnerabilities, moving beyond purely automated detection methods.