cbcvebase.
CVE-2025-48595
published 2026-06-01

CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no…

PriorityP184high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-05
Exploited in the wild
EPSS
1.71%
74.8th percentile
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

7 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid

Detection & IOCsextracted from sources · hover to see the quote

  • Target component is Android Framework; look for local privilege escalation attempts via integer overflow on Android 14, 15, 16, and 16 QPR2 devices
  • Exploitation pattern is consistent with commercial spyware operators targeting high-profile individuals; correlate with known spyware TTPs on Android devices
  • No user interaction is required for exploitation; monitor for unexpected privilege escalation or code execution events in Android Framework processes without any user-initiated action
  • Flag Android devices not yet patched to June 2026 security patch levels (2026-06-01 or 2026-06-05) as at-risk; patch level can be checked in device settings
  • ·Google has confirmed active exploitation but has not released technical details, exploit code, or indicators of compromise; detection must rely on behavioral and patch-level signals
  • ·Patch availability varies by vendor; non-Pixel Android devices may lag behind Google Pixel devices in receiving the June 2026 security updates
  • ·CISA BOD 22-01 remediation deadline is 2026-06-05; federal agencies must apply vendor mitigations or discontinue use of affected Android products by that date

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.4HIGH
cisa8.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.