CISA Warns of Android 0-Day Use-After-Free Vulnerability Exploited in Attacks
## Android 0-Day Use-After-Free Vulnerability
Android 0-Day Use-After-Free Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding a zero-day vulnerability in the Android operating system, identified as CVE-2025-48543 . This high-severity vulnerability could allow attackers to gain elevated control over affected devices.
On Thursday, Sep 4, 2025, the vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating a confirmed and ongoing threat to users. The issue is a use-after-free vulnerability within the Android Runtime (ART), a core component responsible for executing applications on Android devices.
Exploitation of this memory corruption bug can bypass the security confines of the Chrome browser sandbox, resulting in local privilege escalation. This enables attackers to gain higher-level permissions on the device, potentially allowing the installation of persistent malware, access to sensitive user data, or further control over the compromised device.
This high-severity vulnerability could allow attackers to gain elevated control over affected devices.
CISA has issued a directive requiring all Federal Civilian Executive Branch (FCEB) agencies to apply necessary mitigations by a deadline of Sep 25, 2025. If patches are unavailable, agencies must discontinue use of the affected product to prevent compromise.
Google addressed the vulnerability in its September 2025 Android Security Bulletin, released on Sep 1. CISA advises all organizations and individual users to prioritize installing this security update as soon as it becomes available from their device manufacturer.
For Android users, it is crucial to check for and apply the latest system updates immediately. This can typically be done by navigating to Settings > System > System update. Timely patching remains a critical defense against vulnerabilities actively exploited in cyberattacks.
Based on reporting by Cyber Security News.
