Google patches Android RCE under active exploit
Google patched multiple Android vulnerabilities, including CVE-2025-27363, a System component RCE under limited targeted exploitation requiring no user interaction.
Google released its May 2025 Android security bulletin addressing multiple vulnerabilities across Android OS components. The most critical flaw, CVE-2025-27363, affects the System component and enables remote code execution without requiring additional execution privileges or user interaction. Google has confirmed this vulnerability is under limited, targeted exploitation in the wild.
The security update addresses a total of 42 vulnerabilities spanning Framework, System, and third-party components from Arm, Qualcomm, MediaTek, and Imagination Technologies. Beyond the actively exploited RCE, the bulletin includes 19 privilege escalation flaws in Framework and System components, multiple information disclosure issues, and one denial-of-service vulnerability. The privilege escalation vulnerabilities could allow attackers to execute code with elevated permissions within the affected service accounts.
All Android devices running security patch levels prior to May 5, 2025 are affected. Organizations should prioritize patching CVE-2025-27363 immediately given the confirmed exploitation. The impact severity depends on service account privileges, with administrative accounts presenting higher risk than restricted accounts.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2025-047
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free