Google released the December 2025 Android Security Bulletin, patching 107 vulnerabilities, including a critical remote Denial of Service (DoS) flaw (CVE-2025-48631) in the Android Framework and two zero-day vulnerabilities (CVE-2025-48633 and CVE-2025-48572) that are reportedly under active exploitation. The zero-days allow for information disclosure and elevation of privilege, affecting Android versions 13 through 16, and are believed to be targeted in limited attacks. The DoS vulnerability enables remote attackers to crash or disable devices without requiring user interaction or additional execution privileges.
The update is distributed in two patch levels (2025-12-01 and 2025-12-05), covering both core Android components and vendor-specific issues. Google’s disclosure highlights the ongoing threat posed by actively exploited vulnerabilities in the Android ecosystem and underscores the importance of timely patching by device manufacturers and users. The December update represents one of the largest patch releases of the year, following a period of irregular vulnerability reporting from Google.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
After not appearing in CISA's Known Exploited Vulnerabilities catalog when Google published the bulletin, the two exploited Android Framework flaws were later added to KEV. Multiple follow-on reports on December 3 noted the KEV listing for CVE-2025-48633 and CVE-2025-48572.
Google stated that source code for the vulnerabilities fixed in the December bulletin would be released to the Android Open Source Project repository within about 48 hours, by Wednesday after the bulletin's publication. This would make the fixes available to the broader Android ecosystem after the initial bulletin release.
Google released the December 2025 Android Security Bulletin with patch levels 2025-12-01 and 2025-12-05, addressing 107 vulnerabilities across Framework, System, Kernel, and multiple vendor components. The bulletin identified CVE-2025-48631 as the most severe issue and said two Framework flaws, CVE-2025-48633 and CVE-2025-48572, were under limited, targeted exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcescworld.com
Open sourcethecyberthrone.in
Open sourcemalwarebytes.com
Open sourcesecurityaffairs.com
Open sourcesource.android.com
Open sourcesource.android.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.