INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Android and Linux Kernel Exploitation Vulnerabilities Catalog
| 2026-06-03 15:36 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The second vulnerability CISA added to KEV is tracked as CVE-2022-0492, a high-severity privilege escalation flaw that impacts multiple Linux kernel branches from 2.6 through 4.20 and from 5.5 through 5.17. This critical context highlights the severity of the issue, which can be leveraged for increased privileges by hackers exploiting vulnerabilities in the Android Framework. The most recent flaw added to KEV catalog is CVE-2025-48595, a high-severity integer overflow vulnerability that requires no user interaction to exploit and affects Android 14 through 16. Google's security bulletin indicates limited targeted exploitation of this issue but provides specific details about the activity or technical information about the flaw or incidents. The Linux kernel versions addressing the issue are: 4.9.301+; 4.14.266+; 4.19.229+; 5.4.177+; 5.10.97+; 5.15.20+; 5.16.6+. This critical information is essential for federal agencies bound by the BOD 22-01 directive, which requires vendors to apply security updates and mitigations or stop using impacted software.
Technical Mitigations AI-generated
* Implement secure coding practices and follow best security guidelines to prevent exploitation of known vulnerabilities like CVE-2022-0492 and CVE-2025-48595.
* Regularly update and patch Linux kernel versions, including those that address the mentioned flaws (CVE-2022-0492 and CVE-2025-48595), to ensure timely fixes and minimize potential exploits.
* Use secure authentication mechanisms in containerized environments using cgroups v1, such as implementing additional access controls or using more robust authentication methods like Kerberos or OAuth.
* Monitor system logs for signs of exploitation attempts on affected systems, and take prompt action if necessary to prevent further damage.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-0492CVE-2022-0492
CVE-2025-48595CVE-2025-48595
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026/06/01
Threat actors exploited Android and Linux bugs to target the 2026 patch levels.
Click on any entity below to view its context and source!
general_metric
2026 patch levels
The issue has been addressed with the release of June 2026 security patches (2026-06-01 and 2026-06-05 security patch levels).
2026/06/03
Threat actors used an integer overflow vulnerability in the Linux kernel to exploit Android devices.
Click on any entity below to view its context and source!
infrastructure
Linux
The issue is a privilege escalation flaw affecting the Linux kernel feature called control groups (
groups
), that limits, accounts for, and isolates the resource usage (CPU, memory, disk I/O, network, etc.) of a collection of processes.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
Linux Kernel Improper Authentication Vulnerability
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
The first flaw added to the catalog, tracked as
CVE-2022-0492
, can be exploited by an attacker to escape a container to execute arbitrary commands on the container host.
The root cause of the problem is the cgroups implementation in the Linux kernel that did not properly restrict access to the feature.
CISA warns of active attacks exploiting Android, Linux bugs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
organisation
CPU
The issue is a privilege escalation flaw affecting the Linux kernel feature called control groups (
groups
), that limits, accounts for, and isolates the resource usage (CPU, memory, disk I/O, network, etc.) of a collection of processes.
infrastructure
Android
According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
Linux Kernel Improper Authentication Vulnerability
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
The first flaw added to the catalog, tracked as
CVE-2022-0492
, can be exploited by an attacker to escape a container to execute arbitrary commands on the container host.
CISA warns of active attacks exploiting Android, Linux bugs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
The second flaw added to the catalog, tracked as
CVE-2025-48595
(CVSS score of 8.4), affects devices running Android 14, 15, 16, and Android 16 QPR2.
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
According to Google’s
recent security bulletin
, the security issue impacts Android 14 through 16, and requires no user interaction to exploit.
organisation
Google
According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device.
According to Google’s
recent security bulletin
, the security issue impacts Android 14 through 16, and requires no user interaction to exploit.
organisation
CVE-2022
Linux Kernel Improper Authentication Vulnerability
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
The first flaw added to the catalog, tracked as
CVE-2022-0492
, can be exploited by an attacker to escape a container to execute arbitrary commands on the container host.
organisation
CVE-2025-48595
The second flaw added to the catalog, tracked as
CVE-2025-48595
(CVSS score of 8.4), affects devices running Android 14, 15, 16, and Android 16 QPR2.
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
organisation
Known Exploited
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
organisation
KEV
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
infrastructure
Windows
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
Windows Shell and ConnectWise ScreenConnect flaws to its
Known Exploited Vulnerabilities (KEV) catalog
.
organisation
CVE-2022-0492
Below are the flaws added to the catalog:
CVE-2022-0492
(CVSS score of 7.0)
organisation
CVSS
Below are the flaws added to the catalog:
CVE-2022-0492
(CVSS score of 7.0)
organisation
CVE-2025
“There are indications that CVE-2025-48595 may be under limited, targeted exploitation.”
reads the advisory
.
Google indicated that CVE-2025-48595 may be under limited targeted exploitation in the wild, but provided no specific details about the activity or technical information about the flaw or the incidents.
June 2026
The Linux kernel versions 4.9.301+ and 5.10.97+ are required to address the active attacks exploiting Android, Linux bugs.
Click on any entity below to view its context and source!
general_metric
2026 patch levels
The issue has been addressed with the release of June 2026 security patches (2026-06-01 and 2026-06-05 security patch levels).
infrastructure
Linux
The second vulnerability CISA added to KEV is tracked as CVE-2022-0492, a high-severity privilege escalation flaw that impacts
multiple Linux kernel branches
, from 2.6 through 4.20, and from 5.5 through 5.17.
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
4.9.301
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
4.14.266
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
4.19.229
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
5.4.177
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
5.10.97
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
5.15.20
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
5.16.6
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
infrastructure
5.17-rc3
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply the vendor-provided security updates and mitigations, or to stop using the impacted software.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
June 5, 2026
Threat actors are exploiting known vulnerabilities in Android and Linux operating systems to target federal agencies.
June 5
CISA set a deadline of June 5 for patching Android and Linux vulnerabilities.
Click on any entity below to view its context and source!
attribution
CISA
CISA set the
deadline for June 5
.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
The issue is a privilege escalation flaw affecting the Linux kernel feature called control groups (
groups
), that limits, accounts for, and isolates the resource usage (CPU, memory, disk I/O, network, etc.) of a collection of processes.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
Linux Kernel Improper Authentication Vulnerability
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
The first flaw added to the catalog, tracked as
CVE-2022-0492
, can be exploited by an attacker to escape a container to exec…
The root cause of the problem is the cgroups implementation in the Linux kernel that did not properly restrict access to the feature.
The second vulnerability CISA added to KEV is tracked as CVE-2022-0492, a high-severity privilege escalation flaw that impacts
multiple Linux kernel branches
, from 2.6 through 4.20, and from 5.5 through 5.17.
CISA warns of active attacks exploiting Android, Linux bugs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
Android
Affected Product
According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.
Linux Kernel Improper Authentication Vulnerability
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
The first flaw added to the catalog, tracked as
CVE-2022-0492
, can be exploited by an attacker to escape a container to exec…
The second flaw added to the catalog, tracked as
CVE-2025-48595
(CVSS score of 8.4), affects devices running Android 14, 15, 16, and Android 16 QPR2.
CISA warns of active attacks exploiting Android, Linux bugs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system.
The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges.
According to Google’s
recent security bulletin
, the security issue impacts Android 14 through 16, and requires no user interaction to exploit.
Metrics
infrastructure
Windows
Affected Product
The U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
Windows Shell and ConnectWise ScreenConnect flaws to its
Known Exploited Vulnerabilities (KEV) catalog
.
Metrics
infrastructure
4.9.301
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
4.14.266
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
4.19.229
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
5.4.177
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
5.10.97
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
5.15.20
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
5.16.6
Software Version
The Linux kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required…
Metrics
infrastructure
5.17-rc3
Software Version
…kernel versions that address the issue are:
4.9.301+
4.14.266+
4.19.229+
5.4.177+
5.10.97+
5.15.20+
5.16.6+
5.17-rc3+
By including the two flaws in KEV, all federal agencies bound by the BOD 22-01 directive are required to apply t…
Intelligence Sources
BleepingComputer
2026-06-03
CISA warns of active attacks exploiting Android, Linux bugs
BleepingComputer
Security Affairs
2026-06-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
timeline
Temporal Reference
June 5, 2026
date
10x
organisation
Identified Entity
CPU
entity
10x
attribution
Attributing Entity
Known Exploited
authority
8x
infrastructure
Software Version
4.9.301
version
3x
infrastructure
Affected Product
Linux
software
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
2x
vulnerability
Exploited CVE
CVE-2022-0492
cve
2x
vulnerability
CVSS Score
7
score
2x
general metric
%
54
%
Contextual Telemetry
Context Block
3 METRICS
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Qpr2
16
qpr2
general metric
Patch Levels
2,026
patch levels
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.