INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Android and Linux Kernel Exploitation Vulnerabilities Catalog

| 2026-06-03 15:36 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The second vulnerability CISA added to KEV is tracked as CVE-2022-0492, a high-severity privilege escalation flaw that impacts multiple Linux kernel branches from 2.6 through 4.20 and from 5.5 through 5.17. This critical context highlights the severity of the issue, which can be leveraged for increased privileges by hackers exploiting vulnerabilities in the Android Framework. The most recent flaw added to KEV catalog is CVE-2025-48595, a high-severity integer overflow vulnerability that requires no user interaction to exploit and affects Android 14 through 16. Google's security bulletin indicates limited targeted exploitation of this issue but provides specific details about the activity or technical information about the flaw or incidents. The Linux kernel versions addressing the issue are: 4.9.301+; 4.14.266+; 4.19.229+; 5.4.177+; 5.10.97+; 5.15.20+; 5.16.6+. This critical information is essential for federal agencies bound by the BOD 22-01 directive, which requires vendors to apply security updates and mitigations or stop using impacted software.
Technical Mitigations AI-generated
* Implement secure coding practices and follow best security guidelines to prevent exploitation of known vulnerabilities like CVE-2022-0492 and CVE-2025-48595. * Regularly update and patch Linux kernel versions, including those that address the mentioned flaws (CVE-2022-0492 and CVE-2025-48595), to ensure timely fixes and minimize potential exploits. * Use secure authentication mechanisms in containerized environments using cgroups v1, such as implementing additional access controls or using more robust authentication methods like Kerberos or OAuth. * Monitor system logs for signs of exploitation attempts on affected systems, and take prompt action if necessary to prevent further damage.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2022-0492CVE-2022-0492 CVE-2025-48595CVE-2025-48595
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026/06/01
Threat actors exploited Android and Linux bugs to target the 2026 patch levels.
general_metric 2026 patch levels
‎2026/06/03
Threat actors used an integer overflow vulnerability in the Linux kernel to exploit Android devices.
infrastructure Linux
organisation CPU
infrastructure Android
organisation Google
organisation CVE-2022
organisation CVE-2025-48595
organisation Known Exploited
organisation KEV
infrastructure Windows
organisation CVE-2022-0492
organisation CVSS
organisation CVE-2025
‎June 2026
The Linux kernel versions 4.9.301+ and 5.10.97+ are required to address the active attacks exploiting Android, Linux bugs.
general_metric 2026 patch levels
infrastructure Linux
infrastructure 4.9.301
infrastructure 4.14.266
infrastructure 4.19.229
infrastructure 5.4.177
infrastructure 5.10.97
infrastructure 5.15.20
infrastructure 5.16.6
infrastructure 5.17-rc3
organisation EDR
‎June 5, 2026
Threat actors are exploiting known vulnerabilities in Android and Linux operating systems to target federal agencies.
‎June 5
CISA set a deadline of June 5 for patching Android and Linux vulnerabilities.
attribution CISA
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎4.9.301
Software Version
Metrics
infrastructure
‎4.14.266
Software Version
Metrics
infrastructure
‎4.19.229
Software Version
Metrics
infrastructure
‎5.4.177
Software Version
Metrics
infrastructure
‎5.10.97
Software Version
Metrics
infrastructure
‎5.15.20
Software Version
Metrics
infrastructure
‎5.16.6
Software Version
Metrics
infrastructure
‎5.17-rc3
Software Version
Intelligence Sources