logo
Android users placed on red alert - you must check your settings 'immediately'

Android users placed on red alert - you must check your settings 'immediately'

Daily Record07-05-2025
A worrying new Android bug has been discovered and is already being used to target devices.
Android phone users have been warned to make sure their settings are fully up to date, due to a worrying bug targeting them.
The stark warning from security experts after the bug has been found hiding within this hugely popular operating system. Google has now fixed the error, but not before it was handed the dreaded zero-day stamp.

That tag basically means the glitch has already been spotted by hackers and is being actively exploited in the wild. That's why it's so vital everyone makes a quick check without delay, reports the Mirror.

Senior Security Strategy Manager EMEIA at firm Jamf, Adam Boynto said: 'The latest Android Security Bulletin contains a fix for an actively exploited vulnerability, CVE-2025-27363, therefore we advise all Android users to update their devices immediately."
Google always releases monthly patches, which usually fix minor bugs and glitches. However, sometimes the problems are a little more serious and that's why it's vital all phone users make sure they keep on top of installing updates.
'The fixed bug is an out-of-bounds memory vulnerability in the FreeType software,' Jamf's Boynton explained. 'FreeType is a core component of Android devices because it renders fonts and is therefore an attractive target for cybercriminals. Exploiting the vulnerability could allow an attacker to gain control of the entire system without requiring elevated privileges.
'Although this is a targeted attack, most likely targeting high-value individuals, we strongly recommend that all users update their Android OS. The bug has been exploited since March, and its zero-click nature means that criminals can exploit the vulnerability without the user even being aware.'
Google usually rolls out its updates to Pixel devices first with other manufacturers such as Samsung, OnePlus and Honor following soon after the initial release.
No matter what phone you have in your pocket. It's a good idea to head to the settings menu this week and make sure things are fully updated.

Join the Daily Record WhatsApp community!
Get the latest news sent straight to your messages by joining our WhatsApp community today.
You'll receive daily updates on breaking news as well as the top headlines across Scotland.
No one will be able to see who is signed up and no one can send messages except the Daily Record team.
All you have to do is click here if you're on mobile, select 'Join Community' and you're in!
If you're on a desktop, simply scan the QR code above with your phone and click 'Join Community'.
We also treat our community members to special offers, promotions, and adverts from us and our partners. If you don't like our community, you can check out any time you like.
To leave our community click on the name at the top of your screen and choose 'exit group'.
If you're curious, you can read our Privacy Notice.
It comes as an urgent alert was issued to all Gmail users to be aware of a new and sophisticated scam that could compromise their personal data. Last month, an alarming rise in attacks aimed at stealing sensitive information was recorded as hackers target users.
Security experts from Malwarebytes have now stepped in with their warning about this menacing online threat from cybercriminals who are exploiting Google's infrastructure, crafting emails that convincingly seem to be sent directly from the tech firm.
The aim of these online crooks is to trick people into divulging their Google account credentials. Users are urged to exercise caution when checking their email accounts to avoid being deceived. You can read more here.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING
‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING

Scottish Sun

timean hour ago

  • Scottish Sun

‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING

The earlier you update, the better GOOG GOD 'Critical' alert to 3.5bn Google users over 'high-severity' flaw that could hijack your phone without you doing ANYTHING Click to share on X/Twitter (Opens in new window) Click to share on Facebook (Opens in new window) IF you use Google's Chrome browser, stop what you're doing and check for an update right now. Google has pushed a fresh security release for Chrome and is urging its billions of users worldwide to install it as soon as possible. Sign up for Scottish Sun newsletter Sign up 1 The company's advisory amounts to a clear 'update now' warning Credit: Getty The company has confirmed the new Stable Channel build is rolling out across desktop and mobile, with fixes for multiple security issues. It's important to note that you are safest after you have updated and restarted your device. What's the problem? Google has flagged a new batch of security flaws, and you should update ASAP. The most serious is CVE-2025-8901 - a high‑severity bug in ANGLE (the graphics tech Chrome uses). In plain English, a dodgy, specially crafted web page could poke at your device's memory where it shouldn't, which is a big no‑no for security. Google's also outlined two medium‑severity issues: CVE-2025-8881: an 'inappropriate implementation' in the File Picker (the bit that lets you choose files to upload). an 'inappropriate implementation' in the File Picker (the bit that lets you choose files to upload). CVE-2025-8882: a 'use‑after‑free' bug in Aura (Chrome's interface layer), which can cause crashes or open the door to further exploits. The good news is that there's no evidence these have been used in real‑world attacks. But some can be triggered remotely by just visiting a malicious page, so don't sit on it - get the latest Chrome update and restart your browser to lock things down. Why it matters Chrome is the most widely used web browser, making it an attractive target for cybercriminals. The latest update includes security fixes that decrease the risk of exposure to malicious websites and infected downloads. Google usually withholds technical details until most users have installed the updates to prevent alerting attackers. This is why it's important to update your browser promptly. Google has confirmed the latest Stable Channel release of Chrome (the latest Stable Channel release) with security fixes for Windows, Mac, and Linux, with Android and iOS following. The company's advisory amounts to a clear 'update now' warning: install the patch and relaunch the browser to be protected. If you leave it for later, Chrome won't fully apply fixes until you close and reopen it. How to update Chrome in 30 seconds On Windows and Mac Open Chrome and click the three dots (top right) Go to Help > About Google Chrome Chrome will check for updates and download automatically Click Relaunch to finish On Android Open Google Play Store Tap your profile > Manage apps & device > Updates available Find Chrome and tap Update (or search for Chrome and update from the app page) Reopen Chrome when it's done On iPhone and iPad Open the App Store Tap Updates (or your profile > Available Updates) Update Google Chrome Reopen the app On Chromebook (ChromeOS) Click the clock > Settings > About ChromeOS Click Check for updates and Restart to update Google Chrome owners can make single click to stay safe – but beware 'red alert' How to check you're protected You don't need to memorise version numbers. After you've updated: Go to Help > About Google Chrome on desktop If it says 'Chrome is up to date' and you've relaunched, you're covered On mobile, open Chrome > Settings > About Chrome to confirm the latest build is installed If your update hasn't appeared yet, don't panic. Google staggers rollouts globally. Try again later today, or grab the latest installer directly from Google's Chrome site and reinstall over the top on the desktop. Managed work devices may be controlled by your IT team, so check with them if updates are blocked. Frequently asked questions Does Incognito keep me safe from exploits? No. Incognito stops Chrome from saving your browsing history locally. It doesn't shield you from security flaws. You still need updates. Do I need to reinstall Chrome every time there's an update? No. Chrome updates itself; you just need to relaunch. Only reinstall if the updater is broken or your install is corrupted. Will I lose my tabs when I relaunch? Enable 'Continue where you left off' to restore tabs after a relaunch. Is this the same as ETAs/patches I see for Android apps? Separate but similar idea. Chrome on Android updates via Google Play like any app. Desktop Chrome has its own updater. What Google hasn't said (yet) - and why You'll see Google acknowledge 'security fixes' without always listing every vulnerability immediately. That's deliberate. By holding back technical specifics for a short window, they make it harder for bad actors to reverse‑engineer the flaw while users are still patching. The takeaway for you is simple: the earlier you update, the better. Why attackers love browsers Your browser sits between you and the internet. If crooks can trick it, they can: Redirect you to fake banking or shopping pages Run code on your device via malicious websites Plant spyware through drive‑by downloads Steal saved passwords and cookies to hijack accounts That's why Google pushes security releases frequently - small, regular patches that keep the bad guys on the back foot. Signs you might have been hit - and what to do Most modern attacks aim to be invisible, but watch for: New toolbars or extensions you don't recognise The home page or the search engine suddenly changed Pop‑ups and redirects on legit sites Unfamiliar logins or security alerts from your accounts If you spot any of the above:

‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING
‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING

The Sun

timean hour ago

  • The Sun

‘Critical' alert to 3.5bn Google users over ‘high-severity' flaw that could hijack your phone without you doing ANYTHING

IF you use Google's Chrome browser, stop what you're doing and check for an update right now. Google has pushed a fresh security release for Chrome and is urging its billions of users worldwide to install it as soon as possible. 1 The company has confirmed the new Stable Channel build is rolling out across desktop and mobile, with fixes for multiple security issues. It's important to note that you are safest after you have updated and restarted your device. What's the problem? Google has flagged a new batch of security flaws, and you should update ASAP. The most serious is CVE-2025-8901 - a high‑severity bug in ANGLE (the graphics tech Chrome uses). In plain English, a dodgy, specially crafted web page could poke at your device's memory where it shouldn't, which is a big no‑no for security. Google's also outlined two medium‑severity issues: CVE-2025-8881: an 'inappropriate implementation' in the File Picker (the bit that lets you choose files to upload). CVE-2025-8882: a 'use‑after‑free' bug in Aura (Chrome's interface layer), which can cause crashes or open the door to further exploits. The good news is that there's no evidence these have been used in real‑world attacks. But some can be triggered remotely by just visiting a malicious page, so don't sit on it - get the latest Chrome update and restart your browser to lock things down. Why it matters Chrome is the most widely used web browser, making it an attractive target for cybercriminals. The latest update includes security fixes that decrease the risk of exposure to malicious websites and infected downloads. Google usually withholds technical details until most users have installed the updates to prevent alerting attackers. This is why it's important to update your browser promptly. Google has confirmed the latest Stable Channel release of Chrome (the latest Stable Channel release) with security fixes for Windows, Mac, and Linux, with Android and iOS following. The company's advisory amounts to a clear 'update now' warning: install the patch and relaunch the browser to be protected. If you leave it for later, Chrome won't fully apply fixes until you close and reopen it. How to update Chrome in 30 seconds On Windows and Mac Open Chrome and click the three dots (top right) Go to Help > About Google Chrome Chrome will check for updates and download automatically Click Relaunch to finish On Android Open Google Play Store Tap your profile > Manage apps & device > Updates available Find Chrome and tap Update (or search for Chrome and update from the app page) Reopen Chrome when it's done On iPhone and iPad Open the App Store Tap Updates (or your profile > Available Updates) Update Google Chrome Reopen the app On Chromebook (ChromeOS) Click the clock > Settings > About ChromeOS Click Check for updates and Restart to update Google Chrome owners can make single click to stay safe – but beware 'red alert' How to check you're protected You don't need to memorise version numbers. After you've updated: Go to Help > About Google Chrome on desktop If it says 'Chrome is up to date' and you've relaunched, you're covered On mobile, open Chrome > Settings > About Chrome to confirm the latest build is installed If your update hasn't appeared yet, don't panic. Google staggers rollouts globally. Try again later today, or grab the latest installer directly from Google's Chrome site and reinstall over the top on the desktop. Managed work devices may be controlled by your IT team, so check with them if updates are blocked. Frequently asked questions Does Incognito keep me safe from exploits? No. Incognito stops Chrome from saving your browsing history locally. It doesn't shield you from security flaws. You still need updates. Do I need to reinstall Chrome every time there's an update? No. Chrome updates itself; you just need to relaunch. Only reinstall if the updater is broken or your install is corrupted. Will I lose my tabs when I relaunch? Enable 'Continue where you left off' to restore tabs after a relaunch. Is this the same as ETAs/patches I see for Android apps? Separate but similar idea. Chrome on Android updates via Google Play like any app. Desktop Chrome has its own updater. What Google hasn't said (yet) - and why You'll see Google acknowledge 'security fixes' without always listing every vulnerability immediately. That's deliberate. By holding back technical specifics for a short window, they make it harder for bad actors to reverse‑engineer the flaw while users are still patching. The takeaway for you is simple: the earlier you update, the better. Why attackers love browsers Your browser sits between you and the internet. If crooks can trick it, they can: Redirect you to fake banking or shopping pages Run code on your device via malicious websites Plant spyware through drive‑by downloads Steal saved passwords and cookies to hijack accounts That's why Google pushes security releases frequently - small, regular patches that keep the bad guys on the back foot. Signs you might have been hit - and what to do Most modern attacks aim to be invisible, but watch for: New toolbars or extensions you don't recognise The home page or the search engine suddenly changed Pop‑ups and redirects on legit sites Unfamiliar logins or security alerts from your accounts If you spot any of the above:

Google Chrome issues urgent security update to 3,500,000,000 users
Google Chrome issues urgent security update to 3,500,000,000 users

Metro

time5 hours ago

  • Metro

Google Chrome issues urgent security update to 3,500,000,000 users

Google Chrome users have been warned just weeks after a 'high-severity vulnerability' was detected in the browser. Some 3.5 billion users will be offered an update, which will be rolled out in the coming days and weeks. It comes just weeks after Google issued another update for eight identified flaws, and an emergency patch for a high-severity vulnerability. The exact details of the vulnerability and what has been done to fix it have not been specified by Google. But the tech giant said: 'Access to bug details and links may be kept restricted until a majority of users are updated with a fix. 'We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven't yet fixed.' The issues could have been exploited by remote hackers in attacks on users. To update to the latest version of Google and prevent the attacks, go to the Help|About option on the settings menu and follow prompts. Once the update is complete, users must make sure to relaunch their browser to activate the latest version. More Trending The Chrome Stable channel has been updated to 139.0.7258.127/.128 for Windows, Mac and 139.0.7258.127 for Linux. Last month the UK's competition regulator gave an update on their investigation into whether Google has too much power, saying it is a 'key gateway to the internet' and may need to loosen its control. The Competition and Markets Authority (CMA) said today that it is minded to give the tech firm 'strategic market status', after starting to look into this in January This would require Google to follow certain rules around competition with other search engines and ad providers. Get in touch with our news team by emailing us at webnews@ For more stories like this, check our news page. MORE: Man caught naked on patio by Google Street View awarded more than £9,000

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store