logo

CISA warns of active attacks exploiting Android, Linux bugs

ID: e1256e3b-956e-5f2b-b7c5-7c4716a4c875

STIX ID: report--e1256e3b-956e-5f2b-b7c5-7c4716a4c875

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Bill Toulas

...
...

CISA warns that threat actors are exploiting two high-severity flaws: CVE-2025-48595 (Android Framework integer overflow affecting Android 14–16, enabling privilege escalation with no user interaction and reportedly under limited targeted exploitation) and CVE-2022-0492 (Linux kernel cgroups v1 privilege-escalation allowing container escape to host root across many kernel branches). Both CVEs were added to CISA's KEV, require immediate patching by affected organizations, and have vendor fixes available in recent security updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.