Thread updated 7 Oct

Android flaws exploited in the wild

Android, Samsung, Qualcomm, Arm and MediaTek flaws used in attacks, with Android security news.

Started 12 Jun · 2 articles · 16 facts
16 sources

Log in – next time you'll see what's new since your visit.

What happened

Timeline

Anubis Malware in 2026: Android Trojan and Ransomware

Anubis malware is two threats in 2026: the leaked Android banking trojan with a ransomware lock and a separate Windows ransomware group with a wiper mode.

Article →

Is Fortnite Safe on Android in 2026? Malware and Fakes

Fortnite is not a virus, and in 2026 it is back on Google Play. The 2018 Android installer flaw, fake Fortnite APKs that spread malware, and safe steps.

Article →

CVE-2026-58704 added to CISA's exploited list: Google Pixel Improper Authorization Vulnerability

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

2-Spyware: exploited vulnerability →

CVE-2025-48595 added to CISA's exploited list: Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

2-Spyware: exploited vulnerability →

CVE-2026-21385 added to CISA's exploited list: Qualcomm Multiple Chipsets Memory Corruption Vulnerability

Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.

2-Spyware: exploited vulnerability →

CVE-2025-48572 added to CISA's exploited list: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

2-Spyware: exploited vulnerability →

CVE-2025-48633 added to CISA's exploited list: Android Framework Information Disclosure Vulnerability

Android Framework contains an unspecified vulnerability that allows for information disclosure.

2-Spyware: exploited vulnerability →

CVE-2025-21042 added to CISA's exploited list: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.

2-Spyware: exploited vulnerability →

CVE-2025-21043 added to CISA's exploited list: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.

2-Spyware: exploited vulnerability →

CVE-2025-48543 added to CISA's exploited list: Android Runtime Use-After-Free Vulnerability

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.

2-Spyware: exploited vulnerability →

CVE-2025-27038 added to CISA's exploited list: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

2-Spyware: exploited vulnerability →

CVE-2025-21480 added to CISA's exploited list: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

2-Spyware: exploited vulnerability →

CVE-2025-21479 added to CISA's exploited list: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

2-Spyware: exploited vulnerability →

CVE-2024-43093 added to CISA's exploited list: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

2-Spyware: exploited vulnerability →

CVE-2024-43047 added to CISA's exploited list: Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

2-Spyware: exploited vulnerability →

CVE-2024-36971 added to CISA's exploited list: Android Kernel Remote Code Execution Vulnerability

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.

2-Spyware: exploited vulnerability →

CVE-2024-32896 added to CISA's exploited list: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.

2-Spyware: exploited vulnerability →

CVE-2024-4610 added to CISA's exploited list: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

2-Spyware: exploited vulnerability →
2

Articles in this thread

Android flaws exploited in the wild
5,455 members already hereReading, writing, commenting and voting. 0 verified · 180 joined this year