自 2025 年 3 月 27 日起,我們建議您使用 android-latest-release
而非 aosp-main
建構及貢獻 AOSP。詳情請參閱「Android 開放原始碼計畫變更」。
Android 安全性公告 - 2025 年 7 月
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
發布日期:2025 年 7 月 7 日
Android 安全性公告列舉對 Android 裝置造成影響的安全漏洞,並說明相關細節。2025-07-05 之後的安全性修補程式等級已解決這些問題。請參閱檢查及更新 Android 版本一文,瞭解如何查看裝置的安全性修補程式等級。
Android 的合作夥伴至少會提前一個月收到公告中所有問題的相關通知。
這些問題的原始碼修補程式將於接下來 48 小時內發布到 Android 開放原始碼計畫 (AOSP) 存放區,等到相關 Android 開放原始碼計畫連結建立完成後,我們就會修訂這則公告。
公告事項
- 在 2025 年 7 月的 Android 安全性公告中,我們未提供任何 Android 安全性修補程式。
如果想進一步瞭解 Android 安全性平台防護措施和 Google Play 安全防護機制如何加強 Android 平台的安全性,請參閱 Android 和 Google Play 安全防護機制所提供的因應措施。
Android 和 Google 服務的資安因應措施
本節概述 Android 安全性平台和 Google Play 安全防護等服務防護方案所提供的因應措施。這些措施可有效防範有心人士在 Android 系統上惡意運用安全漏洞來達到特定目的。
- Android 平台持續推出新的版本來強化安全性,因此有心人士越來越難在 Android 系統上找出漏洞加以利用。我們建議所有使用者盡可能更新至最新版的 Android。
- Android 安全性團隊透過 Google Play 安全防護主動監控濫用情形,並向使用者警示可能有害的應用程式。在預設情況下,搭載 Google 行動服務的裝置會自動啟用 Google Play 安全防護機制。使用者如果不是從 Google Play 安裝應用程式,這項防護措施格外重要。
常見問題與解答
如果您在閱讀這篇公告後有任何疑問,可參考本節的常見問答。
1. 如何判斷目前的裝置軟體版本已修正這些問題?
請參閱檢查及更新 Android 版本一文,瞭解如何查看裝置的安全性修補程式等級。
- 如果是 2025-07-01 之後的安全性修補程式等級,代表 2025-07-01 安全性修補程式等級涵蓋的所有問題都已解決。
- 如果是 2025-07-05 之後的安全性修補程式等級,代表 2025-07-05 安全性修補程式等級以前的所有問題都已解決。
提供這些更新的裝置製造商應將修補程式字串等級設定為:
- [ro.build.version.security_patch]:[2025-07-01]
- [ro.build.version.security_patch]:[2025-07-05]
如果是搭載 Android 10 以上版本的裝置,Google Play 系統更新的日期字串應與 2025-07-01 安全性修補程式等級相同。如要進一步瞭解如何安裝安全性更新,請參閱這篇文章。
2. 為什麼這篇公告有兩種安全性修補程式等級?
本公告納入兩種安全性修補程式等級,方便 Android 合作夥伴靈活運用,快速修正某些發生在所有 Android 裝置上的類似安全漏洞。我們建議 Android 合作夥伴修正本公告所列的所有問題,並使用最新的安全性修補程式等級。
- 安全性修補程式等級為 2025-07-01 的裝置必須納入所有與該安全性修補程式等級相關的問題,以及在之前安全性公告中回報的所有問題適用的修正程式。
- 如果裝置是使用 2025-07-05 之後的安全性修補程式等級,就必須加入本安全性公告 (以及之前公告) 中的所有適用修補程式。
我們建議合作夥伴將所有問題適用的修補程式都彙整在單一更新中。
3. 「類型」欄中的項目代表什麼意義?
在安全漏洞詳情表中,「類型」欄中的項目代表安全漏洞類別。
縮寫 |
定義 |
RCE |
遠端程式碼執行 |
EoP |
權限提升 |
ID |
資訊外洩 |
DoS |
阻斷攻擊 |
不適用 |
未分類 |
4. 「參考資料」欄中的項目代表什麼意義?
在安全漏洞詳情表中,「參考資料」欄底下的項目可能會包含一個前置字串,表示該參考資料值所屬的機構。
前置字串 |
參考資料 |
A- |
Android 錯誤 ID |
QC- |
Qualcomm 參考編號 |
M- |
MediaTek 參考編號 |
N- |
NVIDIA 參考編號 |
B- |
Broadcom 參考編號 |
U- |
UNISOC 參考編號 |
5. 「參考資料」欄中,Android 錯誤 ID 旁邊的星號 (*) 代表什麼?
在對應的參考資料 ID 旁邊標上星號 (*) 代表該問題並未公開,相關更新通常已納入 Pixel 裝置的最新二進位驅動程式中。您可以前往 Google Developers 網站下載這些驅動程式。
6. 為什麼安全漏洞會分別刊登在這份安全性公告和裝置/合作夥伴安全性公告 (例如 Pixel 公告)?
刊載在此安全性公告的安全漏洞,都是宣告 Android 裝置最新安全性修補程式等級時,必須修正的問題。但裝置/合作夥伴安全性公告所刊載的其他安全漏洞,對於宣告安全性修補程式等級並非必要。Android 裝置和晶片組製造商也可能會針對公司產品發布安全漏洞詳細資料,例如:Google、Huawei、LGE、Motorola、Nokia 或 Samsung。
版本
版本 |
日期 |
附註 |
1.0 |
2025 年 7 月 7 日 |
發布公告 |
這個頁面中的內容和程式碼範例均受《內容授權》中的授權所規範。Java 與 OpenJDK 是 Oracle 和/或其關係企業的商標或註冊商標。
上次更新時間:2025-08-12 (世界標準時間)。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["缺少我需要的資訊","missingTheInformationINeed","thumb-down"],["過於複雜/步驟過多","tooComplicatedTooManySteps","thumb-down"],["過時","outOfDate","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["示例/程式碼問題","samplesCodeIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-08-12 (世界標準時間)。"],[],[],null,["# Android Security Bulletin—July 2025\n\n*Published July 7, 2025*\n\nThe Android Security Bulletin contains details of security vulnerabilities\naffecting Android devices. Security patch levels of\n2025-07-05 or later address all of these issues.\nTo learn how to check a device's security patch level, see\n[Check and update your Android version](https://support.google.com/pixelphone/answer/4457705).\n\nAndroid partners are notified of all issues at least a month before\npublication.\nSource code patches for these issues will be released to the Android Open\nSource Project (AOSP) repository in the next 48 hours. We will revise this\nbulletin with the AOSP links when they are available.\n\nAnnouncements\n-------------\n\n- There are no Android security patches in the July 2025 Android Security Bulletin.\n\nRefer to the [Android and Google Play Protect\nmitigations](#mitigations) section for details on the\n[Android security platform protections](/security/enhancements)\nand Google Play Protect, which improve the security of the Android platform.\n\nAndroid and Google service mitigations\n--------------------------------------\n\nThis is a summary of the mitigations provided by the\n[Android security platform](/security/enhancements) and service\nprotections such as\n[Google Play\nProtect](https://developers.google.com/android/play-protect). These capabilities reduce the likelihood that security\nvulnerabilities could be successfully exploited on Android.\n\n- Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible.\n- The Android security team actively monitors for abuse through [Google Play\n Protect](https://developers.google.com/android/play-protect) and warns users about [Potentially\n Harmful Applications](/static/security/reports/Google_Android_Security_PHA_classifications.pdf). Google Play Protect is enabled by default on devices with [Google Mobile\n Services](http://www.android.com/gms), and is especially important for users who install apps from outside of Google Play.\n\nCommon questions and answers\n----------------------------\n\nThis section answers common questions that may occur after reading this\nbulletin.\n\n**1. How do I determine if my device is updated to address these\nissues?**\n\nTo learn how to check a device's security patch level, see\n[Check and update your Android version](https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices).\n\n- Security patch levels of 2025-07-01 or later address all issues associated with the 2025-07-01 security patch level.\n- Security patch levels of 2025-07-05 or later address all issues associated with the 2025-07-05 security patch level and all previous patch levels.\n\nDevice manufacturers that include these updates should set the patch string level to:\n\n- \\[ro.build.version.security_patch\\]:\\[2025-07-01\\]\n- \\[ro.build.version.security_patch\\]:\\[2025-07-05\\]\n\nFor some devices on Android 10 or later, the Google Play system update\nwill have a date string that matches the 2025-07-01\nsecurity patch level.\nPlease see [this\narticle](https://support.google.com/android/answer/7680439) for more details on how to install\nsecurity updates.\n\n**2. Why does this bulletin have two security patch levels?**\n\nThis bulletin has two security patch levels so that Android partners have the\nflexibility to fix a subset of vulnerabilities that are similar across all\nAndroid devices more quickly. Android partners are encouraged to fix all issues\nin this bulletin and use the latest security patch level.\n\n- Devices that use the 2025-07-01 security patch level must include all issues associated with that security patch level, as well as fixes for all issues reported in previous security bulletins.\n- Devices that use the security patch level of 2025-07-05 or newer must include all applicable patches in this (and previous) security bulletins.\n\nPartners are encouraged to bundle the fixes for all issues they are\naddressing in a single update.\n\n\n**3. What do the entries in the *Type* column mean?**\n\nEntries in the *Type* column of the vulnerability details table\nreference the classification of the security vulnerability.\n\n| Abbreviation | Definition |\n|--------------|------------------------------|\n| RCE | Remote code execution |\n| EoP | Elevation of privilege |\n| ID | Information disclosure |\n| DoS | Denial of service |\n| N/A | Classification not available |\n\n\n**4. What do the entries in the *References* column mean?**\n\nEntries under the *References* column of the vulnerability details\ntable may contain a prefix identifying the organization to which the reference\nvalue belongs.\n\n| Prefix | Reference |\n|--------|---------------------------|\n| A- | Android bug ID |\n| QC- | Qualcomm reference number |\n| M- | MediaTek reference number |\n| N- | NVIDIA reference number |\n| B- | Broadcom reference number |\n| U- | UNISOC reference number |\n\n\n**5. What does an \\* next to the Android bug ID in the *References*\ncolumn mean?**\n\nIssues that are not publicly available have an \\* next to the corresponding\nreference ID. The update for that issue is generally contained in the latest\nbinary drivers for Pixel devices available from the\n[Google Developer site](https://developers.google.com/android/drivers).\n\n**6. Why are security vulnerabilities split between this bulletin and\ndevice/partner security bulletins, such as the\nPixel bulletin?**\n\nSecurity vulnerabilities that are documented in this security bulletin are\nrequired to declare the latest security patch level on Android\ndevices. Additional security vulnerabilities that are documented in the\ndevice/partner security bulletins are not required for\ndeclaring a security patch level. Android device and chipset manufacturers\nmay also publish security vulnerability details specific to their products,\nsuch as\n[Google](/docs/security/bulletin/pixel),\n[Huawei](https://consumer.huawei.com/en/support/bulletin/),\n[LGE](https://lgsecurity.lge.com/security_updates_mobile.html),\n[Motorola](https://motorola-global-portal.custhelp.com/app/software-security-page/g_id/6806),\n[Nokia](https://www.nokia.com/phones/en_int/security-updates), or\n[Samsung](https://security.samsungmobile.com/securityUpdate.smsb).\n\nVersions\n--------\n\n| Version | Date | Notes |\n|---------|--------------|--------------------|\n| 1.0 | July 7, 2025 | Bulletin Published |"]]