CVE-2025-48595
published 2026-06-01CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no…
PriorityP184high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-05
Exploited in the wild
EPSS
1.71%
74.8th percentile
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target component is Android Framework; look for local privilege escalation attempts via integer overflow on Android 14, 15, 16, and 16 QPR2 devices ↗
- →Exploitation pattern is consistent with commercial spyware operators targeting high-profile individuals; correlate with known spyware TTPs on Android devices ↗
- →No user interaction is required for exploitation; monitor for unexpected privilege escalation or code execution events in Android Framework processes without any user-initiated action ↗
- →Flag Android devices not yet patched to June 2026 security patch levels (2026-06-01 or 2026-06-05) as at-risk; patch level can be checked in device settings ↗
- ·Google has confirmed active exploitation but has not released technical details, exploit code, or indicators of compromise; detection must rely on behavioral and patch-level signals ↗
- ·Patch availability varies by vendor; non-Pixel Android devices may lag behind Google Pixel devices in receiving the June 2026 security updates ↗
- ·CISA BOD 22-01 remediation deadline is 2026-06-05; federal agencies must apply vendor mitigations or discontinue use of affected Android products by that date ↗
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.4HIGH
cisa8.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 14/15/16/16-qpr2 integer overflow (WID-SEC-2026-1772)
vuldb·2026-06-03·CVSS 8.4
CVE-2025-48595 [HIGH] Google Android 14/15/16/16-qpr2 integer overflow (WID-SEC-2026-1772)
A vulnerability was found in Google Android 14/15/16/16-qpr2. It has been rated as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2025-48595. An attack has to be approached locally. Furthermore, there is an exploit available.
GHSA
In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
ghsa_unreviewed·2026-06-02
CVE-2025-48595 [HIGH] CWE-190 In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
VulnCheck
Android Framework Integer Overflow Vulnerability
vulncheck·2025·CVSS 8.4
CVE-2025-48595 [HIGH] CWE-190 Android Framework Integer Overflow Vulnerability
Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Affected: Android Framework
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://source.android.com/docs/security/bulletin/2026/2026-06-01; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2026-06-05
CISA
Android Framework Integer Overflow Vulnerability
cisa·2026-06-02·CVSS 8.4
CVE-2025-48595 [HIGH] CWE-190 Android Framework Integer Overflow Vulnerability
Vulnerability: Android Framework Integer Overflow Vulnerability
Affected: Android Framework
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://source.android.com/docs/security/bulletin/2026/2026-06-01 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48595
Remediation Due Date: 2026-06-05
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
blogs_hackernews·2026-06-08·CVSS 8.4
CVE-2025-48595 [HIGH] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked.
A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again. And while everyone chased the loud stuff, quieter attackers sat in inboxes for months, reading mail and stealing it bit by bit.
Lots to cover. Grab coffee. Read up.
## ⚡ Threat of the Week
Miasma Worm Hits 73 Microsoft GitHub Repositories in Supply Chain
Checkpoint
8th June – Threat Intelligence Report
blogs_checkpoint·2026-06-08
CVE-2025-48595 8th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, government IDs, and health insurance details.
Password manager Dashlane has disclosed an attack
Bleepingcomputer
CISA warns of active attacks exploiting Android, Linux bugs
blogs_bleepingcomputer·2026-06-03·CVSS 7.8
CVE-2025-48595 [HIGH] CISA warns of active attacks exploiting Android, Linux bugs
## CISA warns of active attacks exploiting Android, Linux bugs
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
According to Google’s recent security bulletin , the security issue impacts Android 14 through 16, and requires no user interaction to exploit.
Google indicated that CVE-2025-48595 may be under limited targeted exploitation in the wild, but provided no specific details about the activity or technical information
Hackernews
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
blogs_hackernews·2026-06-03·CVSS 8.4
CVE-2025-48595 [HIGH] Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.
Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction. The vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2 (Quarterly Platform Release 2).
"In multiple locations, there is a possible way to
Bleepingcomputer
Google fixes one actively exploited Android zero-day, 124 flaws
blogs_bleepingcomputer·2026-06-02·CVSS 7.8
CVE-2025-48595 [HIGH] Google fixes one actively exploited Android zero-day, 124 flaws
## Google fixes one actively exploited Android zero-day, 124 flaws
## Sergiu Gatlan
"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible."
While Google has yet to share technical details about the flaw or provide more information about the ongoing attacks targeting it, similar flaws have been exploited in the past by commercial spyware and by nation-state operations targeting high-profile or high-interest individuals.
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and e
2026-06-01
Published
2026-06-02
Added to CISA KEV
Exploited in the wild