
CISA warned today that two Android zero-day vulnerabilities are under active attack, within hours of Google releasing patches for the flaws.
Both are high-severity Android framework vulnerabilities. CVE-2025-48572 is a Privilege Escalation vulnerability, while CVE-2025-48633 is an Information Disclosure vulnerability.
Both were among 107 Android vulnerabilities addressed by Google in its December
security bulletin released today.
Android Vulnerabilities CVE-2025-48572 and CVE-2025-48633 Under Attack
Google warned that the CVE-2025-48572 and CVE-2025-48633 framework
vulnerabilities βmay be under limited, targeted exploitation.β
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) followed with its own
alert adding the Android vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
βThese types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant
risks to the federal enterprise,β CISA warned.
βCISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation ofβ―KEV Catalog vulnerabilitiesβ―as part of their
vulnerability management practice,β the U.S. cybersecurity agency added.
The vulnerabilities are so new that the CVE Program lists the CVE numbers as βreserved,β with details yet to be released.
Neither Google nor CISA provided further details on how the vulnerabilities are being exploited.
7 Critical Android Vulnerabilities Also Patched
The December Android
security bulletin also addressed seven critical vulnerabilities, the most severe of which is CVE-2025-48631, a framework Denial of Service (DoS) vulnerability that Google warned βcould lead to remote denial of service with no additional execution privileges needed.β
Four of the critical vulnerabilities affect the Android kernel and are all Elevation of Privilege (EoP) vulnerabilities: CVE-2025-48623, CVE-2025-48624, CVE-2025-48637, and CVE-2025-48638.
The other two critical vulnerabilities affect Qualcomm closed-source components: CVE-2025-47319, an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability, and CVE-2025-47372, a Buffer Overflow vulnerability that could lead to memory corruption.
Google lists CVE-2025-47319 as βCriticalβ while Qualcomm lists the vulnerability as Medium severity; both list CVE-2025-47372 as Critical.
The Qualcomm vulnerabilities are addressed in detail in The Cyber Express article
Qualcomm Issues Critical Security Alert Over Secure Boot Vulnerability published earlier today.