
Google has released an urgent security update to address a critical zero-day flaw in Android (CVE-2025-27363) currently being actively exploited by attackers. All Android users are strongly advised to apply the patch immediately to protect their devices and sensitive data. Â
The flaw, assigned as CVE-2025-27363, enables attackers to execute remote code through specially crafted payloads, potentially leading to full device compromise.Â
Exploitation of this vulnerability has already been observed in targeted campaigns, freeing attackers to access private data, install malicious software, and even take control of infected devices. Â
Google’s latest security bulletin, tied to May 2025’s Android Security Update, includes a fix for CVE-2025-27363. Devices supporting these updates include those running Android 12 and newer versions.Â
Many affected devices will receive Over-The-Air (OTA) updates automatically; users can manually check for updates via their device settings under "System Update."Â Â
Devices from manufacturers such as Samsung, OnePlus, and Xiaomi may see a slight delay in patch availability, as these updates often require vendor-specific modifications and testing. Â
To minimize risk and secure your devices, Google recommends the following steps:
This critical vulnerability affects a broad range of Android devices running unpatched versions of the operating system. Details on specific attack vectors or affected models have not been disclosed to prevent further exploitation, although experts are cautioning that the flaw provides a significant gateway for cybercriminals.Â