The U.S. government cybersecurity agency, CISA, has added two critical Android Framework vulnerabilities to its List of Known Exploited Vulnerabilities (KEV). The move is more than just a technical update—it signals that the vulnerabilities are already being actively exploited in real-world attacks, putting millions of Android devices worldwide at risk.

Vulnerabilities that touch the Android core
The CISA update, published on December 2, 2025, addresses CVE-2025-48572 and CVE-2025-48633— two critical flaws in the Android Framework, the subsystem that controls core functions of the operating system. CISA requires federal agencies and critical organizations to apply security updates by December 23, 2025.
The first vulnerability, CVE-2025-48572, concerns privilege escalation, allowing an attacker to gain system-level access to a compromised device. The second, CVE-2025-48633, concerns information disclosure, making it possible to extract personal data without any action from the user.
See also: King Addons for Elementor: Critical vulnerability in WordPress plugin
Why Google hides technical details
As is common in cases of active exploitation, Google has not released detailed technical information about the vulnerabilities. The reason is simple: disclosing attack mechanismsbefore patches are applied would make it even easier for malicious actors to replicate them.
However, their implications are clear. An attacker who achieves privilege escalation can:
- Install persistent malware
- Modify critical system settings
- Gain full access to sensitive data
- Create backdoors that persist even after reboots
The second vulnerability, which allows information theft, acts as an ideal “accomplice” to the first. Together they create a dangerous attack chain that can lead to a complete compromise of a device.

Increasing targeting of Android devices
Although neither vulnerability has yet been linked to ransomware attacks, their inclusion on the KEV list is a clear indication that malicious actors are already exploiting them.
See also: Vulnerabilities in Picklescan allow malicious PyTorch models to bypass checks
Android devices are one of the most common targets worldwide, due to their huge market share and the frequent delay in updating operating systems by many manufacturers.
Android attacks typically exploit chains of multiple vulnerabilities, aiming to bypass defenses and gain maximum control over the system. This makes it critical for users and organizations to install available patches immediately.
CISA obligations and recommendations
According to Operational Directive BOD 22-01, federal agencies are required to implement available security measures before the December 23 deadline.
Systems that cannot be updated should either be taken out of service or protected with additional layers of security, such as:
- access restriction
- strong network segmentation
- active monitoring for suspicious activity

What Android users should do
For ordinary users, the recommendations are equally important:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Enable automatic system updates
- Check the “Google Play System Update” section for pending updates
- Avoiding applications from untrusted sources
- Regularly check for unrecognized applications or suspicious resource consumption
See also: OpenVPN: Vulnerabilities allow DoS and bypass of security mechanisms
Business administrators are urged to implement organized security update programs and ensure that all corporate Android devices receive patches without delay.
The future of Android security
Attacks on mobile platforms are becoming increasingly targeted and sophisticated. CISA’s new warning is a reminder that protecting devices is not limited to antivirus or basic best practices—it requires constant vigilance, prompt patching, and systematic monitoring for signs of compromise.
Organizations are called upon to address the new vulnerabilities with the utmost seriousness, as attacks on mobile devices are now one of the main entry points for cybercriminals into corporate networks.
