Google Patches 2 Actively Exploited Zero-Days in Android - Update Your Phone NOW

Two actively exploited zero-days (CVE-2025-38352, CVE-2025-48543) are patched in the September 2025 Android update. update your phone now.

Google's September 2025 Android Security Bulletin confirms two zero-day exploits are in the wild. Learn what they are and how to update your Pixel, Samsung, or other Android phone immediately.

 

Google has confirmed that two critical vulnerabilities in Android are being actively exploited by attackers. If you have an Android phone, you need to update it immediately. The September 2025 Android Security Bulletin, which went live late on September 3rd, addresses a total of 120 security flaws, but two of these are zero-day vulnerabilities, meaning hackers were already using them before a fix was available.

What is a Zero-Day and Why Is This Urgent?

A zero-day vulnerability is a software security flaw that is discovered and exploited by attackers before the developer has a chance to release a patch. The term "zero-day" refers to the fact that developers have had zero days to fix the problem. This makes such vulnerabilities particularly dangerous because they leave users defenseless until an update is issued and installed.bleepingcomputer+1

The two actively exploited zero-day vulnerabilities patched in the September update are:

  • CVE-2025-38352: A high-severity flaw in the Android Framework that could allow an attacker to gain elevated privileges.cyberinsider+1

  • CVE-2025-48543: A high-severity flaw in the Linux kernel that could also lead to an attacker gaining higher-level access to a device's systems.securityonline+1

In simple terms, these flaws could allow a malicious app to bypass Android's security permissions and take greater control of your phone. The update also patches a critical remote code execution (RCE) flaw, CVE-2025-48539, which could allow an attacker to run malicious code on a device without any user interaction.bleepingcomputer

How to Update Your Android Phone Now

It is crucial to install the September 2025 security update as soon as it becomes available for your device. The update will have a security patch level of 2025-09-01 or 2025-09-05. Here's a step-by-step guide to check for and install the update on your phone.source.android

For Google Pixel Phones:

  1. Open your phone's Settings app.

  2. Scroll down and tap on System.

  3. Tap System update.

  4. Your phone will check for the update. If available, tap Download and install.

Pixel phones are typically the first to receive these updates directly from Google.source.android

For Samsung Galaxy Phones:

  1. Open the Settings app.

  2. Scroll down and tap on Software update.

  3. Tap on Download and install.

  4. If the update is available, follow the on-screen instructions to install it.

Samsung is generally quick to roll out security patches to its flagship and popular mid-range devices.bleepingcomputer

For Other Android Phones (OnePlus, Motorola, etc.):
The process is similar, though menu names may vary slightly.

  1. Open the Settings app.

  2. Look for a menu item like System, About phone, or Software update.

  3. Find and tap the option to Check for updates or System update.

The delivery of updates can vary by manufacturer and carrier. If you don't see the update immediately, check again in a few days. Given the active exploitation of these flaws, enabling automatic updates is highly recommended.

more alfaiznova.com

Hey there! I’m Alfaiz, a 21-year-old tech enthusiast from Mumbai. With a BCA in Cybersecurity, CEH, and OSCP certifications, I’m passionate about SEO, digital marketing, and coding (mastered four languages!). When I’m not diving into Data Science or AI, you’ll find me gaming on GTA 5 or BGMI. Follow me on Instagram (@alfaiznova, 12k followers, blue-tick!) for more. I also run https://www.alfaiznova.in for gadgets comparision and latest information about the gadgets. Let’s explore tech together!"
NextGen Digital... Welcome to WhatsApp chat
Howdy! How can we help you today?
Type here...