Google fixed a critical remote code execution in Android

Google’s November 2025 Android update fixes two flaws in the System component, including a critical remote code execution issue.
Google’s November 2025 Android security updates addressed two vulnerabilities impacting the System component.
The fixes are included in the 2025-11-01 security patch level, the only patch level released this month by the IT giant.
“The most severe vulnerability in this section could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the bulletin published by Google.
The two vulnerabilities are:
- CVE-2025-48593: an insufficient validation of user input that could lead to remote code execution (RCE). The flaw impacts Android versions 13, 14, 15, and 16.
- CVE-2025-48581: In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates through mainline installations due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. The flaw impacts Android version 16.
The company is not aware of attacks in the wild exploiting these vulnerabilities
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Google)




