Google released security updates for September 2025, fixing 120 security flaws in Android, including two vulnerabilities actively exploited in targeted attacks.
The vulnerabilities are listed below:
By infosecbulletin
/ Saturday , June 13 2026
Anthropic said on Friday it will quickly turn off its best AI models for everyone. This comes after the U.S....
Read More
By infosecbulletin
/ Friday , June 12 2026
A security expert called brutecat shared how an AI-based testing system found over $500,000 in weak spots in Google’s systems...
Read More
By infosecbulletin
/ Friday , June 12 2026
Google has released a big security update for Chrome on desktops. Version 149.0.7827.114/.115 is now out for Windows and Mac....
Read More
By infosecbulletin
/ Thursday , June 11 2026
A security notice has revealed serious flaws in some Dahua products. Network admins need to fix these issues fast. The...
Read More
By infosecbulletin
/ Thursday , June 11 2026
South Korea's privacy regulator said on Thursday (June 11) that the country will fine e-commerce giant Coupang 625 billion won...
Read More
By infosecbulletin
/ Thursday , June 11 2026
Oracle PeopleSoft servers are under attack in ongoing data theft by the ShinyHunters gang, which claim to have stolen data...
Read More
By infosecbulletin
/ Wednesday , June 10 2026
Cybersecurity experts found several serious flaws this week in Windows, Chromium, OpenSSL, Microsoft Exchange, and ServiceNow. Some of these flaws...
Read More
By infosecbulletin
/ Wednesday , June 10 2026
GitHub disabled 73 repositories in four Microsoft groups: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Each repo now shows GitHub’s “This repository...
Read More
By infosecbulletin
/ Wednesday , June 10 2026
A security expert shared a new Microsoft Defender vulnerability called "RoguePlanet" only hours after Microsoft fixed two earlier problems in...
Read More
By infosecbulletin
/ Wednesday , June 10 2026
Microsoft's June 2026 Patch Tuesday updates fix about 200 security flaws found in the company's products. None of the flaws fixed...
Read More
CVE-2025-38352 (CVSS score: 7.4): A privilege escalation flaw in the Linux Kernel component
CVE-2025-48543 (CVSS score: N/A): A privilege escalation flaw in the Android Runtime component
Google stated that both vulnerabilities can cause local privilege escalation without needing extra execution privileges. Additionally, they highlighted that no user interaction is necessary for exploitation.
The tech giant did not reveal how the issues have been weaponized in real-world attacks and if they are being put to use in tandem, but acknowledged there are indications of “limited, targeted exploitation.”
Benoît Sevens of Google’s Threat Analysis Group (TAG) has been credited with discovering and reporting the upstream Linux Kernel flaw, indicating that it may have been abused as part of targeted spyware attacks.
Google has fixed several vulnerabilities in Framework and System components, including remote code execution, privilege escalation, information disclosure, and denial-of-service issues.
Google released two security patches, 2025-09-01 and 2025-09-05, to help Android partners fix vulnerabilities quickly across devices.
“Android partners are encouraged to fix all issues in this bulletin and use the latest security patch level,” Google said.