CISA warns of active attacks exploiting Android, Linux bugs
ID: e1256e3b-956e-5f2b-b7c5-7c4716a4c875
STIX ID: report--e1256e3b-956e-5f2b-b7c5-7c4716a4c875
Feed Name: Bleeping Computer
CISA warns that threat actors are exploiting two high-severity flaws: CVE-2025-48595 (Android Framework integer overflow affecting Android 14–16, enabling privilege escalation with no user interaction and reportedly under limited targeted exploitation) and CVE-2022-0492 (Linux kernel cgroups v1 privilege-escalation allowing container escape to host root across many kernel branches). Both CVEs were added to CISA's KEV, require immediate patching by affected organizations, and have vendor fixes available in recent security updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
