Google Patches 43 Android Vulnerabilities in March 2025 Update, Including Two Zero-Days

Listen to this Post

Google’s Latest Security Update Addresses Critical Threats

Google has rolled out its March 2025 Android security update, fixing 43 vulnerabilities, including two zero-days that have been actively exploited in targeted attacks. One of these, CVE-2024-50302, was used by Serbian authorities to unlock confiscated devices, leveraging a flaw in the Linux kernel’s Human Interface Device (HID) driver. The vulnerability was reportedly exploited through a zero-day exploit chain developed by Cellebrite, an Israeli digital forensics firm.

Amnesty International’s Security Lab uncovered this exploit chain in mid-2024 while investigating logs from a device accessed by Serbian authorities. The chain also included a USB Video Class zero-day (CVE-2024-53104) and an ALSA USB-sound driver zero-day. Google stated that it had identified and patched these vulnerabilities before reports surfaced, sharing fixes with OEM partners in January 2025.

The second zero-day (CVE-2024-43093) addressed in this update is a privilege escalation flaw in the Android Framework. This vulnerability allows local attackers to access sensitive directories due to improper Unicode normalization, bypassing file path filters without requiring execution privileges or user interaction.

In addition to the zero-days, the update fixes 11 vulnerabilities that could enable remote code execution on affected devices. Google issued two patch levels: 2025-03-01 and 2025-03-05. The latter includes additional fixes for third-party and kernel subcomponents, though not all Android devices may receive them.

Google Pixel users will get the update immediately, while other manufacturers may take longer to integrate and distribute the patches. The company previously patched another Android zero-day (CVE-2024-43047) in November 2024, which had been exploited by Serbian authorities in the NoviSpy spyware attacks against activists and journalists.

What Undercode Says:

The March 2025 Android security update highlights an ongoing issue in the cybersecurity landscape: the persistent targeting of mobile devices through zero-day exploits. Here’s a deeper look at what this means for Android users, digital privacy, and the global cybersecurity ecosystem.

  1. The Implications of Zero-Day Exploits in Law Enforcement
    The use of CVE-2024-50302 by Serbian authorities raises concerns about how government agencies exploit security flaws. While forensic tools like Cellebrite’s software are often marketed for legitimate investigations, their use against journalists and activists shows the darker side of digital surveillance.

2. Google’s Response and the Timing of Patches

Google’s claim that it had already developed patches before reports surfaced suggests a proactive approach. However, the delay in public disclosure raises questions about transparency. If vulnerabilities are known and exploited in the wild, should security researchers and users be informed sooner?

  1. The Role of Amnesty International in Exposing Exploits

Amnesty

4. The Risks of Remote Code Execution Vulnerabilities

Beyond the zero-days, 11 vulnerabilities in this update could allow remote code execution. These are among the most dangerous types of flaws, as they let attackers take full control of devices without user interaction. This underlines the need for users to install security updates as soon as they become available.

5. Android’s Fragmentation Problem

While Google issues patches, many Android devices rely on manufacturers to distribute updates, leading to delays. Some users may not receive these fixes for weeks or even months, leaving them vulnerable. This remains a fundamental weakness in Android’s security model.

6. The Growing Market for Exploit Chains

The discovery of a multi-zero-day exploit chain underscores the increasing sophistication of digital forensics tools. Companies like Cellebrite develop these tools for law enforcement, but once an exploit chain exists, it can be sold or leaked, making it a potential threat to a wider audience.

7. The Need for Stronger Device Security

With government agencies actively using exploit chains to unlock devices, users need to take steps to protect their data. Enabling full-disk encryption, using strong passwords, and regularly updating software are crucial defense mechanisms.

8. The Potential for More Undisclosed Exploits

If Serbian authorities and Cellebrite used one zero-day chain, it’s likely that other governments and forensic firms have similar capabilities. This raises broader concerns about undisclosed vulnerabilities still in active use.

9. The Debate Over Lawful Hacking vs. Privacy

The case once again fuels the ethical debate over whether law enforcement should have access to such vulnerabilities. While governments argue that these tools are necessary for crime investigations, critics warn about the potential for abuse and mass surveillance.

10. The Future of Android Security Updates

Google’s rapid patching is commendable, but the cycle of discovering, exploiting, and patching zero-days continues. More investment in security-by-design and real-time threat monitoring is needed to stay ahead of attackers.

Fact Checker Results:

  • Claim: Serbian authorities used a zero-day vulnerability to unlock confiscated Android devices.
  • Fact: Confirmed. Amnesty International’s report provides credible evidence of this exploitation.

  • Claim: Google had already developed fixes before reports emerged.

  • Fact: Partially confirmed. Google stated it shared fixes in January, but independent verification

References:

Reported By: https://www.bleepingcomputer.com/news/security/google-fixes-android-zero-days-exploited-in-targeted-attacks/
Extra Source Hub:
https://www.facebook.com
Wikipedia: https://www.wikipedia.org
Undercode AI

Image Source:

OpenAI: https://craiyon.com
Undercode AI DI v2Featured Image