Google Rolls Out February 2025 Security Patch for Android With 47 Fixes

Google notes that one of the vulnerabilities may be “under limited, targeted exploitation”.

Advertisement
Written by Shaurya Tomer, Edited by Siddharth Suvarna | Updated: 6 February 2025 17:56 IST
Highlights
  • Google's update fixes 47 vulnerabilities of high to critical severity
  • One vulnerability, CVE-2024-53104, is reported to be actively exploited
  • The patch addresses issues in system, framework, and kernel

Google also recently rolled out the February 2025 update for Pixel devices

Photo Credit: Android

Google on Monday released the February 2025 security patch for Android devices. The update brings crucial security fixes for discovered vulnerabilities, ranging from high to critical severity, including one CVE which is said to have been “actively exploited”. Several flaws target devices powered by Arm, Imagination Technologies, MediaTek, Qualcomm, and Unisoc components, while other vulnerabilities affect general system components such as framework and kernel.

February 2025 Security Patch for Android

According to Google's Android Security Bulletin for February 2025, a total of 47 discovered vulnerabilities have been patched with the latest update. Following the rollout, the Mountain View-based technology giant has also released the source code patches for these issues to the Android Open Source Project (AOSP) repository. Google notes that one of the vulnerabilities, with the identifier CVE-2024-53104, is related to the USB Video Class (UVC) driver subcomponent and may be “under limited, targeted exploitation”.

With a high severity and a CVSS score of 7.8, it could lead to “physical escalation of privilege with no additional execution privileges needed”, as per the bulletin. While Google has not shared any other details, the National Vulnerability Database, which is the US government's repository of standards-based vulnerability management data, describes it as a video subsystem flaw in the Linux kernel.

Advertisement

It occurred when the uvc_parse_format function tried handling UVC_VS_UNDEFINED frame but skipped or ignored the undefined frames, parsing them instead. The uvc_parse_streaming function, which calculates the buffer size, created this vulnerability as it tried to calculate the buffer size for the expected frames but did not account for the undefined ones. Thus, its attempt to write data steered past the allocated buffer size, creating an out-of-bounds write.

Advertisement

Out of the 47 vulnerabilities patched with the February 2025 update, only one has been labelled a “critical” severity, CVE-2024-45569. It has a CVSS rating of 9.8. The flaw affects WLAN subcomponent in Qualcomm devices. It also addresses issues related to framework, kernel, platform, and system.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  2. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  3. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  4. Oppo Enco X3s Launched With 55dB ANC, Up to 45 Hours Total Battery Life
  5. Samsung Wallet Adds Digital Car Key Support in India: 5 Things to Know
  6. Moto G67 Power 5G India Launch Date, Key Features Announced
  7. OnePlus 15 Confirmed to Launch in India on This Date
  8. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  1. Realme C85 Pro Hands-On Images Reportedly Reveal Design, Colour Options Ahead of Launch
  2. Vivo X300 Series Launching Today: Know Price, Features and Specifications
  3. NASA’s X-59 Supersonic Jet Takes Historic First Flight, Paving Way for Quiet Supersonic Travel
  4. ASIC Clarifies Crypto Rules; Stablecoins, Tokenised Assets Flagged as Financial Products
  5. SpaceX Launches 28 Starlink Satellites, Lands Falcon 9 Booster in Pacific
  6. Idli Kadai, Starring Dhanush, Now Streaming on Netflix: What You Need to Know
  7. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  8. Grey’s Anatomy Season 22 OTT Release: Know Where to Watch it Online?
  9. Bad Girl OTT Release Date: When and Where to Watch Tamil Drama Online?
  10. Adobe Partners With Google Cloud to Integrate Frontier AI Models Across Its Platforms
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.