Google Android Family January 2025 Routine Security Update Advisory
Overview
Google (https://www.google.com) has released a security update that fixes vulnerabilities in the Android family of products. Users of affected products are advised to update to the latest version.
Affected Products
Android Framework
Android System
Android Imagination Technologies
Android MediaTek Components
Android Qualcomm Components
Resolved Vulnerabilities
Local privilege escalation vulnerabilities without execution privileges in the Android framework (CVE-2024-49724, CVE-2024-49732, CVE-2024-49735, CVE-2024-49737, CVE-2024-49738, CVE-2024-49744, CVE-2024-49745) [2]
Highly-rated remote code execution vulnerabilities in Android systems (CVE-2024-43096, CVE-2024-43770, CVE-2024-43771, CVE-2024-49747, CVE-2024-49748, CVE-2024-49749, CVE-2024-34722, CVE-2024-34730, CVE-2024-43095, CVE-2024-43765, CVE-2024-49742, CVE-2024-49734, CVE-2024-43763, CVE-2024-49736) [2]
Local privilege escalation vulnerability in Android Imagination Technologies (CVE-2024-43704) [2]
Highly rated vulnerabilities in Android MediaTek (WLAN) components (CVE-2024-20154, CVE-2024-20146, CVE-2024-20148, CVE-2024-20105, CVE-2024-20140, CVE-2024-20143, CVE-2024-20144, CVE-2024-20145) [2]
Highly rated vulnerabilities in Android Qualcomm (Closed-source component) components (CVE-2024-21464, CVE-2024-45553, CVE-2024-45558) [2]
Vulnerability Patches
Product-specific Vulnerability Patches were made available with the January 5, 2025 update. For more information on Vulnerability Patches, please see the Referenced Sites documentation.
Referenced Sites
[1] Android Security Bulletins
https://source.android.com/docs/security/bulletin/asb-overview
[2] Android Security Bulletin January 2025
https://source.android.com/docs/security/bulletin/2025-01-01