By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Google fixes actively exploited Android flaws in September update
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Google fixes actively exploited Android flaws in September update
Tech News

Google fixes actively exploited Android flaws in September update

By admin 4 Min Read
Share
SHARE

Google has released the September 2025 security update for Android devices, addressing a total of 84 vulnerabilities, including two actively exploited flaws.

The two flaws that were detected as exploited in zero-day attacks are CVE-2025-38352, an elevation of privilege in the Android kernel, and CVE-2025-48543, also an elevation of privilege problem in the Android Runtime component.

Google noted in its bulletin that there are indications that those two flaws may be under limited, targeted exploitation, without sharing any more details.

The CVE-2025-38352 flaw is a Linux kernel flaw first disclosed on July 22, 2025, fixed in kernel versions 6.12.35-1 and later. It was not previously marked as actively exploited.

The flaw is a race condition in POSIX CPU timers, allowing task cleanup disruption and kernel destabilization, potentially leading to crashes, denial of service, and privilege escalation.

CVE-2025-48543 impacts the Android Runtime, where Java/Kotlin apps and system services execute. It potentially allows a malicious app to bypass sandbox restrictions and access higher-level system capabilities.

Apart from the two actively exploited flaws, Google’s September 2025 update for Android also addresses four critical-severity problems.

The first is CVE-2025-48539, a remote code execution (RCE) problem in Android’s System component.

It allows an attacker within physical or network proximity, such as Bluetooth or WiFi range, to execute arbitrary code on the device without any user interaction or privileges.

The other three critical flaws are CVE-2025-21450, CVE-2025-21483, and CVE-2025-27034, all of which impact Qualcomm’s proprietary components.

According to additional details provided by Qualcomm via its bulletin, CVE-2025-21483 is a memory corruption flaw in the data network stack that occurs when reassembling video (NALUs) from RTP packets.

Attackers can send specially crafted network traffic that triggers out-of-bounds writes, allowing remote code execution without user interaction.

CVE-2025-27034 is an array index validation bug in the multi-mode call processor during PLMN selection from the SOR failed list.

Malicious or malformed network responses can corrupt memory and enable code execution in the modem baseband.

In total, this Android patch release incorporates fixes for 27 Qualcomm components, bringing the total number of fixed flaws to 111. However, these aren’t relevant to devices running on chips from other manufacturers.

For MediaTek-powered devices, details about the latest security fixes are available on the chip vendor’s bulletin.

This latest Android security update covers vulnerabilities impacting Android 13 through 16, though not all flaws impact every version of the mobile OS.

The recommended action is to upgrade to security patch level 2025-09-01 or 2025-09-05 by navigating Settings > System > Software updates > System update > and clicking ‘Check for update.’

Users running Android 12 and earlier should replace their device with a newer model that is actively supported, or use a third-party Android distribution that incorporates the latest security updates.

Samsung has also released its September maintenance update for its flagship devices, including fixes for flaws specific to its custom components, such as One UI.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Actively Exploited, Android, Elevation of Privileges, Kernel, Linux Kernel, Mobile, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Gyokeres defends Sweden team-mate Isak after Liverpool transfer saga
Next Article Dolby Atmos FlexConnect Lets You Place Speakers Anywhere
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?