CISA Issues Alert on Actively Exploited Android Zero-Day Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has identified two critical vulnerabilities within the Android Framework, now included in its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities require immediate attention…
The Cybersecurity and Infrastructure Security Agency (CISA) has identified two critical vulnerabilities within the Android Framework, now included in its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities require immediate attention from organizations and users of Android devices globally.
CVE-2025-48572 : This is a privilege escalation vulnerability that could allow attackers to elevate their access levels on compromised devices, bypassing security restrictions. CVE-2025-48633 : This vulnerability could lead to information disclosure, potentially exposing sensitive user data and system information to unauthorized actors.
Listed on Sat, Dec 2, 2025, these vulnerabilities pose a significant risk to millions of Android devices used in both enterprise and consumer environments.
The inclusion of these vulnerabilities in CISA’s KEV catalog highlights the importance of prioritizing vulnerability management. Organizations need to integrate these vulnerabilities into their security frameworks promptly to mitigate potential threats.
These vulnerabilities require immediate attention from organizations and users of Android devices globally.
For Android-based infrastructures or employee devices, the risks are considerable due to the possibility of full system control and data exfiltration by attackers.
CISA has set a compliance deadline of Tue, Dec 23, 2025, for remediation actions. It is recommended to apply vendor-provided mitigations immediately. If patching is not feasible, discontinuing the use of affected products may be necessary to prevent security breaches.
Organizations should ensure their Mobile Device Management (MDM) systems enforce timely patching and communicate the importance of security updates to all employees. Establishing clear patching schedules in line with CISA's advisory guidance is critical.
CISA offers multiple formats for accessing the KEV catalog, including CSV, JSON, and JSON Schema, to facilitate integration into existing security tools, ensuring broader accessibility for organizations.
Based on reporting by GBHackers.
