VORANT. Threat Intelligence Sign in Get the full feed

Google patches Android zero-days under attack

critical vulnerability government-nationalfinancial-serviceshealthcareeducationtelecommunications

Google's March 2025 Android security update addresses 40+ vulnerabilities including two zero-days exploited in targeted attacks, with remote code execution and privilege escalation flaws.

Google has released its March 2025 security update for Android OS, addressing multiple critical vulnerabilities that affect devices running patch levels prior to 2025-03-05. The most severe vulnerabilities could allow remote code execution with no additional execution privileges required. These flaws span multiple components including the Android Framework, System, and Kernel layers, with eight vulnerabilities enabling remote code execution through client-side exploitation and eleven enabling privilege escalation.

Google has confirmed limited, targeted exploitation of two vulnerabilities: CVE-2024-43093 in Google Play system updates and CVE-2024-50302 in the Kernel component. Both zero-days are being actively exploited in the wild, elevating the urgency of patching. The update also addresses information disclosure and denial-of-service vulnerabilities across Framework and System components.

The security bulletin includes patches for vulnerabilities in third-party components from MediaTek and Qualcomm, both open and closed-source. Organizations are advised to apply the March 2025 security patch immediately, particularly given the confirmed exploitation of two vulnerabilities. The MS-ISAC has classified the risk level as high for government and business users, with moderate risk for home users.

Mentioned in this report

Vulnerabilities CVE-2023-21125CVE-2024-0032CVE-2024-43093KEVCVE-2024-46852CVE-2024-50302KEVCVE-2025-0074CVE-2025-0075CVE-2025-0078CVE-2025-0079CVE-2025-0080CVE-2025-0084CVE-2025-0087CVE-2025-22403CVE-2025-22404CVE-2025-22405CVE-2025-22406CVE-2025-22408CVE-2025-22409CVE-2025-22410CVE-2025-22411CVE-2025-22412

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2025-025

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free