ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google Patches Actively Exploited Android Flaw Affecting Millions of Devices

criticalVulnerability exploited in the wildimportance 60CVE-2025-48595

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48595
Integer Overflow Local Privilege Escalation in Android Framework

CVE-2025-48595 is an integer overflow (CWE-190) in the Android Framework, present in multiple locations, that can be triggered by code already running locally on the device with no additional execution privileges and no user interaction required. A local attacker, such as a malicious or compromised app, who triggers the overflow can achieve code execution with elevated privileges, yielding a local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.4, local attack vector). The flaw affects the Android Framework component of Google's Android operating system, so it applies broadly across the Android device ecosystem; specific affected version ranges were not published in the available data. Google fixed the flaw in its June 2026 Android security update, which patched 124 flaws overall, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-02, with news coverage confirming it is being actively exploited in the wild. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply Google's June 2026 Android security update (or later) to all Android devices as soon as the OEM build is available, and verify the device's 'Android security patch level' reads June 2026 or later before treating it as remediated. US federal agencies must remediate within the BOD 22-01 timelines per the KEV listing. Because exploitation requires local code execution, prioritize devices on which users can install or run untrusted apps, and use MDM tooling to track patch compliance across managed fleets.

8.42% KEV
  • Google Android
masshundreds of millions of Android devices potentially exposed (news coverage reports millions of affected devices)
Full article547 words · extracted from securityaffairs.com · click to collapse

Google fixed 124 Android flaws, including CVE-2025-48595, an actively exploited privilege escalation bug linked to targeted attacks.

Google has released its June 2026 Android security updates, fixing 124 vulnerabilities across the mobile operating system. One flaw, tracked as CVE-2025-48595 (CVSS score of 8.4) stands out from the rest because it is already being exploited in attacks in the wild.

The vulnerability affects devices running Android 14, 15, 16, and Android 16 QPR2. According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device. An attacker could exploit the flaw to gain elevated access to the system without requiring additional privileges.

Google has confirmed that there are indications the flaw is being exploited in what it describes as “limited, targeted exploitation.”

“There are indications that CVE-2025-48595 may be under limited, targeted exploitation.” reads the advisory.

The company has not disclosed who is behind the attacks, how many victims may have been affected, or how the vulnerability is being delivered.

That lack of detail is not unusual. When Google uses the phrase “limited, targeted exploitation,” it typically refers to attacks against a small number of carefully selected targets rather than mass exploitation campaigns. In previous Android cases, vulnerabilities carrying the same wording were later linked to commercial spyware vendors or state-sponsored operations targeting journalists, political figures, dissidents, executives, and government officials.

At this stage, there is no public evidence connecting CVE-2025-48595 to a specific threat actor. However, several indicators point toward a sophisticated attack chain rather than ordinary cybercrime. The flaw is local, requires no user interaction, and resides inside the Android Framework, one of the most sensitive layers of the operating system. Researchers believe the most likely scenario involves a malicious application that abuses the vulnerability after installation to gain elevated privileges and potentially full control of the device.

This is exactly the type of capability that attracts commercial surveillance vendors. A spyware operator doesn’t need to infect millions of devices. Compromising a handful of high-value targets is often enough. The economics are very different from ransomware. One successful infection can be worth far more than a large-scale criminal campaign.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.

Beyond CVE-2025-48595, Google patched a number of additional vulnerabilities in the Android System component, including flaws that could also result in privilege escalation. The company released two patch levels, 2026-06-01 and 2026-06-05. Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.

The biggest challenge remains Android’s fragmented update model. Pixel devices receive patches immediately, while many other manufacturers require additional testing and customization before distributing updates. As a result, some users may remain exposed for weeks or months after a vulnerability becomes public. Attackers know this. In many cases, the race begins not when a vulnerability is discovered, but when the patch is released.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Google)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/193057/breaking-news/google-patches-actively-exploited-android-flaw-affecting-millions-of-devices.html