Google’s April 2025 Android Update: Zero-Day Drama and Serbian Shenanigans!

Google’s April 2025 security update patches 62 Android vulnerabilities, including zero-days exploited by Serbian authorities with Cellebrite’s help. The star of the show is a privilege-escalation flaw in the USB-audio driver. Meanwhile, Pixel users get the VIP treatment with immediate updates, leaving other Android devices to wait in line.

Pro Dashboard

Hot Take:

Google’s latest security update is like an Easter egg hunt for hackers, except the eggs are zero-days, and the basket is the Android ecosystem. While Serbian authorities may have thought they hit the jackpot with their exploit chain, Google was quick to rain on their parade with a patch party. Remember, folks, not all Easter eggs are meant to be found!

Key Points:

  • Google released patches for 62 Android vulnerabilities, including two zero-days.
  • The first zero-day is a high-severity privilege escalation in the Linux kernel’s USB-audio driver.
  • The second zero-day allows for information disclosure due to an out-of-bounds read.
  • Amnesty International discovered the exploit chain used by Serbian authorities.
  • Google’s updates are immediately available for Pixel devices, but other Android devices may experience delays.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?