Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Android Issues Security Update to Patch Actively Exploited 0-Day Flaws

Google has issued the Android Security Bulletin for September 2025, addressing multiple high-severity vulnerabilities that are actively exploited.

Google has issued the Android Security Bulletin for September 2025, addressing multiple high-severity vulnerabilities that are actively exploited.

The security patch level 2025-09-05 or later is essential to protect Android devices from these threats.

This update is urgent due to two CVEs being under limited, targeted exploitation.

The most severe vulnerability affects the System component and could enable remote code execution without the need for additional privileges or user interaction.

Critical Vulnerabilities Under Active Exploitation

The vulnerabilities' severity rating assumes platform and service mitigations are disabled for development or bypassed by attackers, highlighting the potential for serious compromise.

The security update addresses vulnerabilities across multiple Android components, focusing on the Android Runtime and System components.

CVE Reference Type Severity

CVE-2025-38352 A-425282960 EoP (Elevation of Privilege) High

Google has issued the Android Security Bulletin for September 2025, addressing multiple high-severity vulnerabilities that are actively exploited.
Robert Langley · Thehackingpost

CVE-2025-48543 A-421834866 EoP (Elevation of Privilege) High

Both vulnerabilities are classified as Elevation of Privilege (EoP) with High severity ratings.

CVE-2025-38352 affects the Android Runtime component, linked to upstream kernel issues.

CVE-2025-48543 impacts Android versions 13, 14, 15, and 16, indicating widespread security concerns across the Android ecosystem.

Android partners were informed of these vulnerabilities at least one month prior to public disclosure, adhering to Google's responsible disclosure practices.

Source code patches will be released to the Android Open Source Project (AOSP) repository within 48 hours of the bulletin publication.

Advertisement

Users are advised to check their device's security patch level and install available updates immediately.

The security team strongly encourages updating to the latest version of Android, as newer versions include enhanced security protections that make exploitation more difficult.

This security bulletin underscores a critical moment for Android security due to the active exploitation of these vulnerabilities.

Google and the Android security team's rapid response demonstrates their commitment to protecting Android devices worldwide from sophisticated cyber threats.

The coordinated disclosure and patching process, along with enhanced monitoring through Google Play Protect, showcase the multi-layered approach necessary to maintain security in today's complex mobile threat landscape.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories