ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

criticalVulnerability exploited in the wildimportance 60CVE-2025-48595

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48595
Integer Overflow Local Privilege Escalation in Android Framework

CVE-2025-48595 is an integer overflow (CWE-190) in the Android Framework, present in multiple locations, that can be triggered by code already running locally on the device with no additional execution privileges and no user interaction required. A local attacker, such as a malicious or compromised app, who triggers the overflow can achieve code execution with elevated privileges, yielding a local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.4, local attack vector). The flaw affects the Android Framework component of Google's Android operating system, so it applies broadly across the Android device ecosystem; specific affected version ranges were not published in the available data. Google fixed the flaw in its June 2026 Android security update, which patched 124 flaws overall, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-02, with news coverage confirming it is being actively exploited in the wild. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply Google's June 2026 Android security update (or later) to all Android devices as soon as the OEM build is available, and verify the device's 'Android security patch level' reads June 2026 or later before treating it as remediated. US federal agencies must remediate within the BOD 22-01 timelines per the KEV listing. Because exploitation requires local code execution, prioritize devices on which users can install or run untrusted apps, and use MDM tooling to track patch compliance across managed fleets.

8.42% KEV
  • Google Android
masshundreds of millions of Android devices potentially exposed (news coverage reports millions of affected devices)
Full article327 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 02, 2026Vulnerability / Mobile Security

Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.

Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction. The vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2 (Quarterly Platform Release 2).

"In multiple locations, there is a possible way to achieve code execution due to an integer overflow," according to a description of the vulnerability on CVE.org. "This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."

Google has acknowledged there are indications that CVE-2025-48595 may be under "limited, targeted exploitation." As is typically the case, the tech giant did not reveal any specifics about who may have been behind the activity, the targets affected, and the scale of such efforts.

That said, similar flaws have been weaponized by commercial spyware vendors to target high-profile individuals as part of extremely targeted attacks.

Elsewhere, a number of vulnerabilities have been patched in the System component, the most severe of which could lead to local escalation of privilege with no additional execution privileges needed.

Google has released two sets of patches - 2026-06-01 and 2026-06-05 security patch levels - with the latter including all fixes from the first set, along with patches for kernel and third-party chipset components from Imagination Technologies, MediaTek, Qualcomm, and Unisoc.

Update

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/google-june-2026-android-update-patches.html