Android Devices at Risk: Critical Zero-Click Vulnerability Actively Exploited — Urgent Security Update Issued
In its May 2025 security bulletin, Google has disclosed a series of Android vulnerabilities, the most pressing being a high-risk flaw tracked as CVE-2025-27363. This vulnerability, embedded in the core System component, is confirmed to be under active exploitation, prompting immediate concern from the cybersecurity community.
CVE-2025-27363 enables attackers to execute code locally on affected devices without any user input or elevated privileges. This zero-click threat significantly increases the risk profile for users on Android 13 and 14, who are strongly advised to install the latest security update without delay.
The flaw arises from a memory management bug within the FreeType library, widely used for font rendering across Android systems. A technical breakdown reveals that a mishandled data type conversion—where a signed short is improperly cast to an unsigned long—results in faulty buffer allocation. As a consequence, attackers can trigger an out-of-bounds write, potentially leading to remote code execution.
What makes this threat particularly urgent is the scale of exposure: FreeType is integrated into over a billion devices, amplifying the potential impact. Google’s acknowledgment of “limited, targeted exploitation” further underscores the need for swift remediation.
Cybersecurity specialists are sounding the alarm and urging all Android users to apply the latest patch immediately to close this critical security gap and defend against known active threats.
Risk Overview
| Category | Information |
|---|---|
| Impacted Software | FreeType font rendering library, version 2.13.0 and earlier |
| Potential Consequences | Execution of unauthorized code due to memory corruption vulnerabilities |
| Conditions for Exploitation | – Use of a vulnerable FreeType build – Parsing of crafted TrueType GX or variable font data – No user action required to trigger the exploit |
| Severity Rating (CVSS 3.1) | 8.1 / 10 – High risk |
Android Security Update Guidance: Check Your Patch Level Now
To streamline vulnerability management and improve transparency, Google assigns a “security patch level” to each Android update, letting users and device makers confirm what issues have been resolved.
The critical flaw disclosed this month—along with numerous other vulnerabilities—is fully addressed in updates marked with a patch level of 2025-05-05 or newer. If your device hasn’t yet received this update, your system may remain exposed.
To verify your patch status and ensure you’re protected:
- Open Settings
- Tap About Phone
- Look for Android Version and Security Patch Level
On devices running Android 10 and above, it’s also worth checking Google Play system updates—these can deliver important security fixes independently of full OS updates.
This May 2025 update underscores a vital message: mobile threats are active and evolving. Staying secure isn’t just about avoiding risky behavior—it’s about keeping your software current.




