Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
Banner Ancharia Mobile 1
Banner Desktop
Two Android Vulnerabilities Actively Exploited: Google Releases Critical Patches

Two Android Vulnerabilities Actively Exploited: Google Releases Critical Patches

6 August 2025 15:58

Google has released the August security updates for Android, which contain patches for six vulnerabilities. Two of these are related to Qualcomm components and have already been exploited in targeted attacks. The vulnerabilities under attack have been identified with the identifiers CVE-2025-21479 and CVE-2025-27038, and the Android security team became aware of them as early as January 2025.

The first issue (CVE-2025-21479) is related to incorrect authorization in the graphics framework, which can cause Memory corruption due to the execution of unauthorized commands in the GPU micromodule based on a certain command sequence.

The second issue (CVE-2025-27038) is a use-after-free bug that causes memory corruption when using Adreno GPU drivers for rendering in Chrome.

It’s important to note that Google included the patches announced by Qualcomm in the update back in June of this year. At the time, the manufacturer warned that, according to information from the Google Threat Analysis Group, the vulnerabilities CVE-2025-21479, CVE-2025-21480, and CVE-2025-27038 could be exploited “in limited targeted attacks.”

“In May, OEM partners were provided with fixes for issues affecting the Adreno graphics processing unit (GPU) driver, along with a strong recommendation to deploy the update to affected devices as soon as possible,” Qualcomm said at the time.

Additionally, with the August update release, Google fixed a critical vulnerability in the system component (CVE-2025-48530). This issue could be exploited for unprivileged remote code execution, but only when combined with other bugs. No user interaction was required.

Traditionally, Google developers released two update levels: 2025-08-01 and 2025-08-05. The latter includes all the patches from the former, plus fixes for closed-source components and kernel subsystems that may not apply to all Android devices.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.