Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Google Patches 120 Flaws, Including Two Zero-Days Under Attack

Posted on September 3, 2025September 3, 2025 By CWS

Sep 03, 2025Ravie LakshmananMobile Safety / Vulnerability
Google has shipped safety updates to deal with 120 safety flaws in its Android working system as a part of its month-to-month fixes for September 2025, together with two points that it mentioned have been exploited in focused assaults.
The vulnerabilities are listed under –

CVE-2025-38352 (CVSS rating: 7.4) – A privilege escalation flaw within the Linux Kernel part
CVE-2025-48543 (CVSS rating: N/A) – A privilege escalation flaw within the Android Runtime part

Google mentioned each vulnerabilities may result in native escalation of privilege with no extra execution privileges wanted. It additionally famous that no person interplay is required for exploitation.

The tech large didn’t reveal how the problems have been weaponized in real-world assaults and if they’re being put to make use of in tandem, however acknowledged there are indications of “restricted, focused exploitation.”
Benoît Sevens of Google’s Menace Evaluation Group (TAG) has been credited with discovering and reporting the upstream Linux Kernel flaw, indicating that it might have been abused as a part of focused adware assaults.
Additionally patched by Google are a number of distant code execution, privilege escalation, info disclosure, and denial-of-service vulnerabilities impacting Framework and System parts.
Google has launched two safety patch ranges, 2025-09-01 and 2025-09-05, in order to provide flexibility to Android companions to deal with a portion of vulnerabilities which might be comparable throughout all Android gadgets extra shortly.
“Android companions are inspired to repair all points on this bulletin and use the newest safety patch degree,” Google mentioned.
Final month, the tech large Google launched safety updates to resolve two Qualcomm vulnerabilities — CVE-2025-21479 (CVSS rating: 8.6) and CVE-2025-27038 (CVSS rating: 7.5) — that have been flagged by the chipmaker as actively exploited within the wild.

The Hacker News Tags:Attack, Flaws, Google, Including, Patches, ZeroDays

Post navigation

Previous Post: Iranian Hackers Exploit 100+ Embassy Email Accounts in Global Phishing Targeting Diplomats
Next Post: OpenAI Set to Acquire Analytics Platform Statsig in $1.1 Billion Agreement

Related Posts

Critical Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks and Persistent Access The Hacker News
npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels The Hacker News
ScarCruft Uses RokRAT Malware in Operation HanKook Phantom Targeting South Korean Academics The Hacker News
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM Credentials The Hacker News
Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands The Hacker News
MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data
  • New Phishing Attack Bypasses Using UUIDs Unique to Bypass Secure Email Gateways
  • OpenAI ChatGPT Atlas Browser Jailbroken to Disguise Malicious Prompt as URLs
  • Ransomware Actors Targeting Global Public Sectors and Critical Services in Targeted Attacks
  • Malicious NuGet Packages Mimic as Popular Nethereum Project to Steal Wallet Keys

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data
  • New Phishing Attack Bypasses Using UUIDs Unique to Bypass Secure Email Gateways
  • OpenAI ChatGPT Atlas Browser Jailbroken to Disguise Malicious Prompt as URLs
  • Ransomware Actors Targeting Global Public Sectors and Critical Services in Targeted Attacks
  • Malicious NuGet Packages Mimic as Popular Nethereum Project to Steal Wallet Keys

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News