Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisory

Critical Zero-Click RCE Vulnerability (CVE-2025-48593) in Android System Component

Updated 3mo agoFirst seen Nov 5, 20253 sources

Google released a security update in November 2025 to address a critical remote code execution vulnerability, CVE-2025-48593, in the Android System component. This flaw allows attackers to execute code remotely on affected devices running Android versions 13 through 16 without requiring user interaction or additional execution privileges. The vulnerability stems from insufficient validation of user input, making it possible for exploitation via a zero-click attack vector.

The update also addressed a separate privilege escalation issue, CVE-2025-48581, affecting Android 16, but the primary concern is the zero-click RCE, which requires immediate patching due to its severity. Google has stated that there is no evidence of active exploitation in the wild at the time of the update. Security experts urge all users and organizations to apply the November 2025 security patch promptly to mitigate the risk posed by this critical vulnerability.

Share:
Critical Zero-Click RCE Vulnerability (CVE-2025-48593) in Android System Component
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 4, 20258mo ago

Reports warn CVE-2025-48593 affects Android 13 through 16

Subsequent reporting described CVE-2025-48593 as a zero-click RCE in Android's core System component affecting Android versions 13 through 16, and urged rapid patching by device makers and users. The flaw was characterized as enabling silent remote compromise of targeted devices.

Nov 1, 20258mo ago

Google says no in-the-wild exploitation is known for patched Android flaws

At the time of the November 2025 Android security bulletin, Google stated it was not aware of active exploitation of CVE-2025-48593 or the other patched System component issue. This accompanied disclosure of the fixes in the monthly update.

Google releases November 2025 Android patch for CVE-2025-48593

Google issued its November 2025 Android security update with the 2025-11-01 security patch level, fixing CVE-2025-48593, a critical remote code execution flaw in the Android System component. The vulnerability requires no additional privileges and no user interaction to exploit.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
1 linked
Android
Organizations
2 linked
GoogleSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.