## Two Android Zero-Days Exploited in the Wild
Two high-severity Android bugs were exploited as zero-days before google issued a fix, according to its December Android security bulletin.
The two vulnerabilities are CVE-2025-48633, an information-disclosure flaw in Android’s framework component, and CVE-2025-48572, an elevation-of-privilege bug also in the framework component. Both are ranked high severity, and according to Google, both “may be under limited, targeted exploitation.”
Both of these – plus an additional 105 security holes – all have patches, so it’s an excellent idea to update your android software ASAP.
Google didn’t provide any details about who is exploiting the vulnerabilities, nor to what end, but we know that commercial spyware and government-sponsored attackers like to exploit these types of mobile device zero-days for snooping purposes.
December 2025 Android Security Update: Qualcomm Flaws and 107 Patches Released
Table of Contents
A new security bulletin from Qualcomm details 107 security vulnerabilities affecting Android devices, including a critical buffer overflow flaw. The December 2025 security update addresses a range of issues, from information disclosure to potential remote code execution, impacting a wide array of device manufacturers. These updates are arriving ahead of Microsoft’s anticipated patch Tuesday event on December 9th, which is expected to bring further security enhancements.
critical Vulnerabilities Highlighted
Qualcomm’s advisory specifically calls out two significant vulnerabilities:
* CVE-2025-47319: This vulnerability allows for information disclosure and exposes internal Trusted Application (TA) to TA dialog APIs to the Host Linux Operating System (HLOS). This could potentially allow unauthorized access to sensitive data. You can find more details in the Qualcomm Security Bulletin.
* CVE-2025-47372: A critical buffer overflow flaw, this vulnerability occurs when a corrupted Executable and Linkable Format (ELF) image – essentially a program file – with an oversized file size is read into a buffer without proper authentication. This could allow an attacker to potentially execute arbitrary code on the device. Further information is available in the Qualcomm Security Bulletin.
What This Means for Android Users
These vulnerabilities, and the 105 others addressed in the update, represent potential risks to the security and privacy of Android device users. A buffer overflow, like CVE-2025-47372, is particularly serious as it can lead to complete system compromise. Information disclosure vulnerabilities,such as CVE-2025-47319,can expose sensitive data to malicious actors.
Patching is Crucial
Device manufacturers are now responsible for incorporating these patches into their own software updates and distributing them to users. Android users should ensure they install the latest security updates as soon as they become available.
Here’s how to check for updates on your Android device:
- Open your device’s Settings app.
- Navigate to System (this may vary slightly depending on your device manufacturer).
- Tap on System update.
- Follow the on-screen instructions to check for and install any available updates.
Looking Ahead
The release of these 107 patches underscores the ongoing need for vigilance in Android security. With Microsoft’s Patch Tuesday event looming, users can anticipate further security updates throughout December. Staying up-to-date with these patches is the best defense against evolving threats and ensures the continued security of your Android device.
key Takeaways:
* Qualcomm has released a security bulletin detailing 107 Android security vulnerabilities.
* CVE-2025-47319 allows information disclosure.
* CVE-2025-47372 is a critical buffer overflow flaw.
* Users should promptly install the latest security updates from their device manufacturer.
* Further updates are expected during Microsoft’s Patch Tuesday on December 9th.
Related reading