Google released security updates for September 2025, fixing 120 security flaws in Android, including two vulnerabilities actively exploited in targeted attacks.
The vulnerabilities are listed below:
By infosecbulletin
/ Thursday , July 23 2026
Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
By infosecbulletin
/ Thursday , July 23 2026
ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
By infosecbulletin
/ Thursday , July 23 2026
SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
By infosecbulletin
/ Wednesday , July 22 2026
The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
By infosecbulletin
/ Saturday , July 18 2026
A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
By infosecbulletin
/ Saturday , July 18 2026
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
By infosecbulletin
/ Friday , July 17 2026
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
By infosecbulletin
/ Thursday , July 16 2026
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
CVE-2025-38352 (CVSS score: 7.4): A privilege escalation flaw in the Linux Kernel component
CVE-2025-48543 (CVSS score: N/A): A privilege escalation flaw in the Android Runtime component
Google stated that both vulnerabilities can cause local privilege escalation without needing extra execution privileges. Additionally, they highlighted that no user interaction is necessary for exploitation.
The tech giant did not reveal how the issues have been weaponized in real-world attacks and if they are being put to use in tandem, but acknowledged there are indications of “limited, targeted exploitation.”
Benoît Sevens of Google’s Threat Analysis Group (TAG) has been credited with discovering and reporting the upstream Linux Kernel flaw, indicating that it may have been abused as part of targeted spyware attacks.
Google has fixed several vulnerabilities in Framework and System components, including remote code execution, privilege escalation, information disclosure, and denial-of-service issues.
Google released two security patches, 2025-09-01 and 2025-09-05, to help Android partners fix vulnerabilities quickly across devices.
“Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level,” Google said.