The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two Android Framework vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling that both issues are being abused in real-world attacks and should be treated as patching priorities. The new entries, CVE-2025-48572 and CVE-2025-48633, affect the Android Framework component that underpins many higher-level APIs used by apps.
According to technical writeups, CVE-2025-48572 is an elevation-of-privilege bug that can allow a malicious application to run code with higher permissions than intended, while CVE-2025-48633 is an information-disclosure vulnerability that can expose data across privilege boundaries. Both flaws were already identified in Google’s December 2025 Android Security Bulletin, which documented more than 100 vulnerabilities impacting Android 13 through 16 and noted limited, targeted exploitation of the two Framework issues in the wild.
An advisory from the Canadian Centre for Cyber Security confirms that CISA moved to include the pair of CVEs in the KEV database on December 2, 2025, shortly after the Android bulletin was published. The Canadian guidance reiterates that organizations should promptly apply the December 2025 Android updates and stresses that KEV inclusion reflects evidence of active exploitation rather than theoretical risk.
Further reporting indicates that CISA has set a December 23, 2025 deadline for U.S. federal civilian executive branch agencies to remediate the vulnerabilities under Binding Operational Directive 22-01. That directive requires agencies to fix KEV-listed flaws within prescribed timelines or document mitigations, and CISA encourages critical infrastructure operators and private-sector defenders to use the catalog as a de facto list of high-priority issues.
For mobile security teams, the additions highlight the exposure created by smartphones and tablets in both corporate and bring-your-own-device (BYOD) fleets. Because the affected Framework component supports core Android services used by many apps, successful exploitation can provide a path to broader device compromise when combined with other weaknesses.
Security advisories from multiple vendors stress the importance of enforcing Android patch levels of at least 2025-12-05 on managed devices, monitoring for installation of untrusted applications, and validating that mobile threat-defense tools are tuned to detect exploitation attempts linked to the newly flagged CVEs.
Sources: Security Affairs, Canadian Centre for Cyber Security, The Hacker News, SOCRadar, Cybersecurity News
—
By the ID Tech Editorial Team