Google released a security update in November 2025 to address a critical remote code execution vulnerability, CVE-2025-48593, in the Android System component. This flaw allows attackers to execute code remotely on affected devices running Android versions 13 through 16 without requiring user interaction or additional execution privileges. The vulnerability stems from insufficient validation of user input, making it possible for exploitation via a zero-click attack vector.
The update also addressed a separate privilege escalation issue, CVE-2025-48581, affecting Android 16, but the primary concern is the zero-click RCE, which requires immediate patching due to its severity. Google has stated that there is no evidence of active exploitation in the wild at the time of the update. Security experts urge all users and organizations to apply the November 2025 security patch promptly to mitigate the risk posed by this critical vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting described CVE-2025-48593 as a zero-click RCE in Android's core System component affecting Android versions 13 through 16, and urged rapid patching by device makers and users. The flaw was characterized as enabling silent remote compromise of targeted devices.
At the time of the November 2025 Android security bulletin, Google stated it was not aware of active exploitation of CVE-2025-48593 or the other patched System component issue. This accompanied disclosure of the fixes in the monthly update.
Google issued its November 2025 Android security update with the 2025-11-01 security patch level, fixing CVE-2025-48593, a critical remote code execution flaw in the Android System component. The vulnerability requires no additional privileges and no user interaction to exploit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.