TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Google Patches 107 Flaws Including 2 Android Zero-Days

Akinola Ajibola by Akinola Ajibola
December 2, 2025
in Security
Share on FacebookShare on Twitter

Google has issued the Android security bulletin for December 2025, which addresses 107 vulnerabilities, including two issues that are currently exploited in targeted attacks.

CVE-2025-48633 and CVE-2025-48572 are the two high-severity vulnerabilities identified. They are information disclosure and elevation-of-privilege problems that impact Android versions 13-16.

More details on the zero-day exploited flaws are CVE-2025-48633 which describes an information disclosure issue in the Android Framework component and CVE-2025-48572 which also describes a privilege escalation issue discovered in the Android Framework.

The December Android advisory team stated that there are indications that the following may be under limited, targeted exploitation.

Exploiting these issues could allow attackers to get sensitive information or greater levels of system access on a vulnerable device.

While Google has not provided any technical or exploitation information regarding the weaknesses, comparable flaws have previously been leveraged for targeted exploitation by commercial spyware or nation-state operations aimed at a small number of high-interest persons.

CVE-2025-48631, a denial-of-service (DoS) issue in the Android Framework, is the most severe vulnerability fixed this month, in order of severity.

This month’s upgrades fix 51 weaknesses in Android Framework and System components, which are covered by the 2025-12-01 Patch Level, as well as 56 issues in the Kernel and third-party closed-source components that are covered by the 2025-12-05 Patch Level.

There are four critical-severity updates for elevation-of-privilege problems in the kernel’s Pkvm and UOMMU subcomponents, as well as two critical fixes for Qualcomm-powered devices (CVE-2025-47319 and CVE-2025-47372).

Qualcomm and MediaTek’s security bulletins for December 2025 contain more details about closed-source solutions.

Samsung also released a security bulletin, which included transferred improvements from the Google update as well as vendor-specific changes. 

While the updates target Android 13 and above, certain essential patches may also roll out to Android 10 and later via Google Play system updates.

Furthermore, Play Protect can detect and stop known malware and attack chains, thus users of any Android version should maintain the component up to date and active.

Those running older Android versions should either use a third-party distribution that contains Google’s security fixes on a regular basis, or upgrade to a newer device model for active support.

To reduce these dangers, users should upgrade their Android devices as soon as possible. Google Pixel smartphones often receive updates instantly, although other manufacturers deliver patches on their own schedules. 

Check for updates on the specified android device and open the settings application.

Go to System > System Update (or About Phone > Software Updates, depending on the device brand).

To protect yourself from any risks, make sure your device’s security patch level is 2025-12-05 or later.

Also users can find further information in the official Android Security Bulletin for December 2025.

Related Posts:

  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • Qualcomm
    Zero-Day Flaw in Qualcomm Chips Exploited to Attack…
  • chrome1
    Google Warns 3.5 Billion Chrome Users Of High-Risk Update
  • Apple_google-partner-on-covid-19-contact-tracing-technology_04102020_LP_hero.jpg.og
    Emergency Zero-Day Patch Updates From Apple & Google
  • 2026-05-08-Linux_LPE-Dirty_Frag-Aufmacher-3f0ce52bb528ed97
    New Linux Zero-Day Flaw 'Dirty Frag' With Root…
  • instagram-1 (1)
    Google Urges Instagram Updates to Fix Android Battery Drain
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • android_17_os_verification_google_main_1778753538832
    Google Announces New OS Verification Tool To Fight Fake OS

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: androidAndroid securityCVE-2025-48572CVE-2025-48633google
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Ready-made LMS and custom development. Pros and cons of each path. June 11, 2026
  • TELCOs Pay 75 Million Users For Poor Network Service June 10, 2026
  • Anthropic Launches Claude Fable 5, Bringing Mythos-Class AI to the Public June 10, 2026
  • Discord Data Breach Reportedly Impacts Over 10 Million Users June 10, 2026
  • TikTok Removed Four Million Videos & Disrupted 86,000 LIVE Sessions In Nigeria June 10, 2026
  • Apple Adds Streaming-Style Subscription Packages To The App Store June 9, 2026
  • Apple Rolls Out Tailored App Store Recommendations June 9, 2026
  • Instagram Rolls Out Custom Profile Grid Arrangement Feature June 9, 2026
  • Signal Argues UK’s Device-Scanning Plan For Nude Images Threatens User Security June 9, 2026
  • UK Regulator Tells Social Media Firms To Stop Viral Illegal Content June 9, 2026
  • Apple Intelligence Gets Major AI Upgrade With New Siri, Safari Tools and Gemini-Powered Models June 9, 2026
  • Gogs Fixes Critical Zero-Day Bug That Enabled Remote Code Execution June 8, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.