Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

TensorWave raises $100M to grow its AMD-powered cloud infrastructure

May 14, 2025

Vulnerabilities Patched by Juniper, VMware and Zoom 

May 14, 2025

Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances

May 14, 2025
Facebook X (Twitter) Instagram
Trending
  • TensorWave raises $100M to grow its AMD-powered cloud infrastructure
  • Vulnerabilities Patched by Juniper, VMware and Zoom 
  • Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances
  • Resilience launches AI-powered Cyber Risk Calculator to quantify financial cyber exposure
  • Trump meets Syria’s al-Sharaa, eyes normalisation of ties with Damascus | Donald Trump News
  • Intellect Design Arena appoints Dave Thomas to lead credit unions and mid-market FI expansion
  • ING launches ‘check the call’ anti-fraud tool in Belgium to combat impersonation scams
  • This is Trump’s moment to deliver peace to the Middle East | Israel-Palestine conflict
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Wednesday, May 14
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Android Update Patches Two Exploited Vulnerabilities
Cybersecurity

Android Update Patches Two Exploited Vulnerabilities

adminBy adminApril 8, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 16


Google on Monday rolled out the April 2025 security update for Android, which resolves two kernel vulnerabilities already exploited in the wild.

The flaws, tracked as CVE-2024-53150 and CVE-2024-53197, impact the ALSA: usb-audio component and were addressed in the Linux kernel in December 2024.

In its advisory, Google notes that the two security defects “may be under limited, targeted exploitation”, without providing additional information on them.

In February, however, Amnesty International revealed that CVE-2024-53197 had been exploited by Cellebrite’s mobile forensic tools to extract data from the device of a Serbian student activist.

The tool was seen exploiting two additional vulnerabilities, namely CVE-2024-53104 and CVE-2024-50302, which were addressed in Android in February and March, respectively. Exploitation of these types of vulnerabilities requires physical access via USB to a device and enables the extraction of data from locked smartphones. 

It is worth noting that there have been no reports of CVE-2024-53150 being exploited in attacks prior to Google’s advisory. However, given that it’s similar to CVE-2024-53197, the flaw is likely part of the same batch of vulnerabilities exploited by Cellebrite, according to the developers of the security- and privacy-focused mobile operating system GrapheneOS.

In addition to these two flaws, Android’s April 2025 update addresses roughly 60 other issues, including three bugs in Project Mainline components.

According to Google, the most severe of these security defects is CVE-2025-26416, an elevation of privilege vulnerability in the System component that impacts Android 13, 14, and 15.

Advertisement. Scroll to continue reading.

“The most severe of these issues is a critical security vulnerability in the System component that could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation,” the internet giant explains.

The flaw was resolved with Android’s 2025-04-01 security patch level, which fixes 28 bugs, split evenly between the Framework and System components. Two other issues are rated ‘critical severity’.

The second part of this month’s update arrives on devices as the 2025-04-05 security patch level and addresses 31 vulnerabilities in Kernel, Arm, Imagination Technologies, MediaTek, and Qualcomm components.

On Monday, Google announced that no security patches specific to Automotive OS and Wear OS were included in this month’s updates for these operating systems — the updates still include the regular Android patches.

Users are advised to update their devices to a security patch level of 2025-04-05, which includes fixes for all the vulnerabilities in the April 2025 Android security bulletin.

Related: Qualcomm Extends Security Support for Android Devices to 8 Years

Related: First Android Update of 2025 Patches Critical Code Execution Vulnerabilities

Related: Android Zero-Day Exploited in Spyware Campaigns, Amnesty International Points to Cellebrite

Related: Google Open Sources Security Patch Validation Tool for Android



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Vulnerabilities Patched by Juniper, VMware and Zoom 

May 14, 2025

Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances

May 14, 2025

Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers

May 14, 2025

ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact 

May 14, 2025

Adobe Patches Big Batch of Critical-Severity Software Flaws

May 13, 2025

Microsoft to Lay Off About 3% of Its Workforce

May 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Skechers’ Greenbergs Set To Pocket Up To $1.1 Billion From Sale To 3G

May 6, 2025

Skechers founders Robert Greenberg (left) and Michael Greenberg (right) started the brand more than 30…

Trump Organization Admits President Still Controls His Business

May 6, 2025

Forbes Richest Person In Every State 2025

April 30, 2025

These Billionaire Signers Of The Giving Pledge Signers On Why The Philanthropy Group Still Matters

April 29, 2025
Our Picks

TensorWave raises $100M to grow its AMD-powered cloud infrastructure

May 14, 2025

Vulnerabilities Patched by Juniper, VMware and Zoom 

May 14, 2025

Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances

May 14, 2025

Resilience launches AI-powered Cyber Risk Calculator to quantify financial cyber exposure

May 14, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

TensorWave raises $100M to grow its AMD-powered cloud infrastructure

May 14, 2025

Attend TechCrunch Sessions: AI with this new, limited-time discount

May 13, 2025

xAI’s promised safety report is MIA

May 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.