Cybersecurity

Android Under Fire: Google Patches Actively Exploited Zero-Days Across Android 13–16

December 12, 20252 min read

Google has issued an urgent Android security update after confirming that multiple zero-day vulnerabilities are being actively exploited in the wild.


With billions of devices running Android globally, this month’s bulletin represents one of the most critical patch cycles of the year — especially for users running Android 13 through 16.

Threat actors are already leveraging two high-severity Framework vulnerabilities, prompting immediate action from users, enterprises, and OEMs.


🔥 Zero-Days Actively Exploited: CVE-2025-48633 & CVE-2025-48572

Google confirmed that attackers are currently exploiting two vulnerabilities inside the Android Framework, the core system layer responsible for app permissions, data handling, and interprocess communication.

CVE-2025-48633 — Information Disclosure (Actively Exploited)

A high-severity flaw that allows unauthorized access to sensitive device data.
Impacts: Android 13, 14, 15, and 16

CVE-2025-48572 — Elevation of Privilege (Actively Exploited)

Allows attackers to gain system-level privileges without additional permissions — a serious risk for data theft, unauthorized actions, and lateral movement.
Impacts: Android 13, 14, 15, and 16

These flaws give attackers powerful leverage over compromised devices — especially when chained with other vulnerabilities.


🚨 Most Severe Issue This Month: CVE-2025-48631 (Remote DoS)

While the two exploited vulnerabilities are urgent, Google identified an even more severe flaw:

CVE-2025-48631 — Remote Denial-of-Service (No Privileges Required)

This vulnerability can be exploited remotely and without authentication, giving attackers the ability to crash targeted devices on demand.

This makes it the most dangerous issue in December’s bulletin and a top-priority patch for all Android users.


🛡️ What Else Google Patched

This month’s security update addresses 30+ vulnerabilities across multiple Android components:

Framework

  • Multiple privilege escalation bugs

  • Information disclosure flaws

  • DoS vulnerabilities across Android 13–16
    Notable CVEs: CVE-2025-22420, CVE-2025-48525

System & Kernel Layers

Fixes for OS components responsible for secure data handling and device stability.

Google Play System Updates

Play Protect continues scanning for malware exploiting these vulnerabilities in the wild.

Google also confirmed source-code patches will be published to the Android Open Source Project (AOSP) within 48 hours.


📱 Who Is Affected?

All users running:

  • Android 13

  • Android 14

  • Android 15

  • Android 16

OEMs were notified one month in advance, giving manufacturers time to prepare device-specific security updates.

However, actual patch availability depends on the device brand — making manual checks essential.


🧭 Elliptic Systems Recommendations

To protect against ongoing exploitation, all Android users should act immediately:

1. Install the December 5, 2025, security update

Go to:
Settings → Security → Security Update

2. Verify your patch level

Check under:
Settings → About Phone → Android Version

3. Keep Google Play Protect enabled

Play Protect automatically blocks apps attempting to exploit these vulnerabilities.

4. Only install apps from the Google Play Store

Side-loading apps significantly increases exploitation risk.

5. Enterprises should enforce MDM-level update compliance

Especially for BYOD and frontline devices.

When attackers are already exploiting Android zero-days, patching becomes a now, not later, requirement.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog