ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google fixes actively exploited Android vulnerability (CVE-2025-48595)

criticalVulnerability exploited in the wildimportance 60CVE-2025-48595

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48595
Integer Overflow Local Privilege Escalation in Android Framework

CVE-2025-48595 is an integer overflow (CWE-190) in the Android Framework, present in multiple locations, that can be triggered by code already running locally on the device with no additional execution privileges and no user interaction required. A local attacker, such as a malicious or compromised app, who triggers the overflow can achieve code execution with elevated privileges, yielding a local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.4, local attack vector). The flaw affects the Android Framework component of Google's Android operating system, so it applies broadly across the Android device ecosystem; specific affected version ranges were not published in the available data. Google fixed the flaw in its June 2026 Android security update, which patched 124 flaws overall, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-02, with news coverage confirming it is being actively exploited in the wild. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply Google's June 2026 Android security update (or later) to all Android devices as soon as the OEM build is available, and verify the device's 'Android security patch level' reads June 2026 or later before treating it as remediated. US federal agencies must remediate within the BOD 22-01 timelines per the KEV listing. Because exploitation requires local code execution, prioritize devices on which users can install or run untrusted apps, and use MDM tooling to track patch compliance across managed fleets.

8.42% KEV
  • Google Android
masshundreds of millions of Android devices potentially exposed (news coverage reports millions of affected devices)
Full article369 words · extracted from helpnetsecurity.com · click to collapse

Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.”

CVE-2025-48595 exploited

About CVE-2025-48595

CVE-2025-48595 is an integer overflow vulnerability in the Android Framework, a set of APIs and system services that apps interact with directly.

The flaw allows attackers to escalate privileges on a vulnerable device, and they may gain complete access to the device and data on it.

Successful exploitation does not hinge on user interaction, and the attack vector is local, which most likely means that the vulnerability is being exploited via a malicious app that targeted users have been tricked into installing.

CVE-2025-48595 is present across Android versions 14, 15, 16, and 16-qpr2 (Quarterly Platform Release 2).

The vulnerability’s NVD description seems to suggest that there are several vulnerable code paths, and hopefully Google’s patch has closed all of them off.

More vulnerabilities addressed

The June 2026 security updates will also patch other critical and high-severity vulnerabilities in the Android Framework, System (core Android daemons and services), Google Play system components, the Linux kernel, and third-party chipset components.

Core Android OS fixes are addressed at patch level 2026-06-01, while devices running patch level 2026-06-05 or later will receive the full set of fixes, including those for kernel and chipset components.

“We notify our Android partners of all issues at least a month before publishing the bulletin,” Google noted, and said that Android device and chipset manufacturers may also publish security vulnerability details specific to their products.

“Within 48 hours after the initial publication of this bulletin, we will release the corresponding source code patches to the Android Open Source Project (AOSP) repository,” the company added.

UPDATE (June 3, 2026, 05:05 a.m. ET):

The team behind GrapheneOS, the privacy and security-focused mobile operating system based on Android and designed primarily for Google Pixel devices, says that Google disclosed CVE-2025-48595 to OEMs in a security preview release near the end of September 2025, and that the GrapheneOS maintainers included the patch in their 2025092501 release.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/02/android-vulnerability-exploited-cve-2025-48595/