# Google patches Android zero-days under attack

Published: 2026-06-09 · Severity: critical · Sectors: government-national, financial-services, healthcare, education, telecommunications
Canonical: https://vorant.io/reports/e7680fd1-d650-4e93-920f-5b1bef9a1913/google-patches-android-zero-days-under-attack

> Google's March 2025 Android security update addresses 40+ vulnerabilities including two zero-days exploited in targeted attacks, with remote code execution and privilege escalation flaws.

Google has released its March 2025 security update for Android OS, addressing multiple critical vulnerabilities that affect devices running patch levels prior to 2025-03-05. The most severe vulnerabilities could allow remote code execution with no additional execution privileges required. These flaws span multiple components including the Android Framework, System, and Kernel layers, with eight vulnerabilities enabling remote code execution through client-side exploitation and eleven enabling privilege escalation.

Google has confirmed limited, targeted exploitation of two vulnerabilities: CVE-2024-43093 in Google Play system updates and CVE-2024-50302 in the Kernel component. Both zero-days are being actively exploited in the wild, elevating the urgency of patching. The update also addresses information disclosure and denial-of-service vulnerabilities across Framework and System components.

The security bulletin includes patches for vulnerabilities in third-party components from MediaTek and Qualcomm, both open and closed-source. Organizations are advised to apply the March 2025 security patch immediately, particularly given the confirmed exploitation of two vulnerabilities. The MS-ISAC has classified the risk level as high for government and business users, with moderate risk for home users.

## Mentioned in this report

- Vulnerabilities: CVE-2023-21125, CVE-2024-0032, CVE-2024-43093 (KEV), CVE-2024-46852, CVE-2024-50302 (KEV), CVE-2025-0074, CVE-2025-0075, CVE-2025-0078, CVE-2025-0079, CVE-2025-0080, CVE-2025-0084, CVE-2025-0087, CVE-2025-22403, CVE-2025-22404, CVE-2025-22405, CVE-2025-22406, CVE-2025-22408, CVE-2025-22409, CVE-2025-22410, CVE-2025-22411, CVE-2025-22412

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2025-025

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e7680fd1-d650-4e93-920f-5b1bef9a1913/google-patches-android-zero-days-under-attack.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
