Google Issues Critical Update for All Pixel Users: Attacks Confirmed
Google has issued a critical update for all Pixel users, addressing two severe vulnerabilities in the Android operating system. These vulnerabilities, CVE-2025-48633 and CVE-2025-48572, are already being exploited, posing a significant risk to users. The U.S. Cyber Defense Agency (CISA) has also issued a warning, instructing federal employees to update or discontinue using their phones.
Google's December 2025 software update is available for all supported Pixel devices running Android 16. The update aims to patch these critical vulnerabilities, which can lead to remote denial of service, requiring no additional execution privileges. The speed and efficiency of Google's update process are notable, ensuring seamless installation and minimizing downtime for users.
This update highlights the advantage of Google's Pixel smartphones over Samsung's Galaxy devices. While Google's users receive their updates promptly, Samsung's users often face a longer wait, with updates rolling out over the course of the month. This delay can result in a slower and more disruptive update process for Samsung users.
Google advises Pixel owners to check for system updates and install the latest software. For government employees, the update is mandatory by December 23rd, or they should power down their devices. Given the confirmed attacks, all users are strongly encouraged to update their devices promptly to mitigate the risk of exploitation.