logo

Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks

ID: 3ed2808c-db1e-534e-a358-b57449d66db1

STIX ID: report--3ed2808c-db1e-534e-a358-b57449d66db1

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Ashish Khaitan

...
...

Google's June 2026 Android security update addresses 124 vulnerabilities, highlighted by an actively exploited high-severity integer overflow zero-day (CVE-2025-48595) in the Android Framework that allows local privilege escalation without user interaction; Google reports limited targeted exploitation and the issue is listed in CISA's KEV. Affected Android 14–16 devices should be patched immediately; enterprises should enforce patch levels via MDM/MAM, restrict untrusted app installs, enable Play Protect, and monitor for privilege escalation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.