INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Google Patches Actively Exploited Android Flaw Affecting Millions
| 2026-06-03 09:44 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The recent patching of a critical Android vulnerability, CVE-2025-48595, has sent shockwaves through the tech industry. This flaw, which affects devices running Android 14 to Android 16 QPR2, is already being exploited in targeted attacks by threat actors. The economics are very different from ransomware, with Google's patching of this issue resulting in millions of device updates across the mobile operating system. However, unlike traditional malware, this vulnerability requires no user interaction and resides within the Android Framework, a highly sensitive layer of the operating system. As a result, it is unlikely to be linked to specific threat actors or attributed to state-sponsored operations. The patching of this issue by Google has sent a strong message that security will not be compromised in exchange for profit, highlighting the importance of prioritizing cybersecurity in the tech industry.
Technical Mitigations AI-generated
* Implement a secure patching mechanism to ensure timely and effective fixes for identified vulnerabilities, such as the use of automated testing and validation tools.
* Conduct thorough vulnerability assessments and penetration testing before deploying patches to identify potential exploitation vectors and mitigate risks.
* Develop and implement robust incident response plans to quickly contain and remediate security incidents, including procedures for isolating affected devices and notifying stakeholders in a timely manner.
* Regularly review and update patching strategies to ensure they remain effective against evolving threats, such as by incorporating new vulnerability detection tools and techniques into the patching process.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-48572CVE-2025-48572
CVE-2025-48595CVE-2025-48595
CVE-2025-48633CVE-2025-48633
CVE-2026-21385CVE-2026-21385
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
March 2025
Threat actors used a vulnerability in the Google Android operating system to target affected devices.
Click on any entity below to view its context and source!
infrastructure
Android
"There are indications that CVE-2025-48595 may be under limited, targeted exploitation,"
the company said
on Monday in its March 2025 Android Security Bulletin.
vulnerability
CVE-2025-48595
"There are indications that CVE-2025-48595 may be under limited, targeted exploitation,"
the company said
on Monday in its March 2025 Android Security Bulletin.
organisation
CVE-2025
"There are indications that CVE-2025-48595 may be under limited, targeted exploitation,"
the company said
on Monday in its March 2025 Android Security Bulletin.
2026/05/03
Threat actors exploited vulnerabilities in the Google Android operating system.
Click on any entity below to view its context and source!
infrastructure
Android
"
Last month, Google also overhauled its Android and Chrome vulnerability rewards programs,
offering bounties of up to $1.5 million
for some Android exploits while scaling back payouts for flaws that are easier to find using artificial intelligence (AI).
2026/06/01
Google released two sets of patches for the June 2026 Android update, with the latter bundling fixes from the first batch and targeting closed-source third-party and kernel subcomponents.
Click on any entity below to view its context and source!
infrastructure
Android
On Monday, Google issued two sets of patches: the
2026-06-01
and
2026-06-05
security patch levels, with the latter bundling all fixes from the first batch, along with patches for closed-source third-party and kernel subcomponents that may not apply to all Android devices.
June 2, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on June 2, 2026, requiring Federal Civilian Executive Branch agencies to remediate the flaw by June 5, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-48595
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
Federal Civilian Executive Branch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
FCEB
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
Jun 02, 2026
Threat actors exploited a previously unknown vulnerability in the Google June 2026 Android update.
2026/06/03
Google released patches for the CVE-2025-48595 vulnerability in June 2026, which affects devices running Android versions 14 and later.
Click on any entity below to view its context and source!
infrastructure
Android
In previous Android cases, vulnerabilities carrying the same wording were later linked to
commercial spyware vendors
or state-sponsored operations targeting journalists, political figures, dissidents, executives, and government officials.
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices
Google fixed 124 Android flaws, including CVE-2025-48595, an actively exploited privilege escalation bug linked to targeted attacks.
According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device.
Beyond CVE-2025-48595, Google patched a number of additional vulnerabilities in the Android System component, including flaws that could also result in privilege escalation.
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices.
The vulnerability affects devices running Android 14, 15, 16, and Android 16 QPR2.
The flaw is local, requires no user interaction, and resides inside the Android Framework, one of the most sensitive layers of the operating system.
The biggest challenge remains Android’s fragmented update model.
The vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2 (Quarterly Platform Release 2).
Google fixes one actively exploited Android zero-day, 124 flaws.
Local attackers can exploit the actively abused high-severity Android Framework vulnerability (tracked as CVE-2025-48595) to gain code execution and escalate privileges on devices running Android 14 or later.
"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform.
We encourage all users to update to the latest version of Android where possible.
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and elevate privileges on unpatched Android devices.
organisation
CVE-2025-48595
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices
Google fixed 124 Android flaws, including CVE-2025-48595, an actively exploited privilege escalation bug linked to targeted attacks.
Local attackers can exploit the actively abused high-severity Android Framework vulnerability (tracked as CVE-2025-48595) to gain code execution and escalate privileges on devices running Android 14 or later.
organisation
Android System
Beyond CVE-2025-48595, Google patched a number of additional vulnerabilities in the Android System component, including flaws that could also result in privilege escalation.
organisation
Google Patches Actively
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices.
organisation
Google
Google fixes one actively exploited Android zero-day, 124 flaws.
"
Google has acknowledged there are indications that CVE-2025-48595 may be under "limited, targeted exploitation."
organisation
System
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and elevate privileges on unpatched Android devices.
organisation
Framework
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and elevate privileges on unpatched Android devices.
organisation
CVE-2025
“There are indications that CVE-2025-48595 may be under limited, targeted exploitation.”
reads the advisory
.
"
Google has acknowledged there are indications that CVE-2025-48595 may be under "limited, targeted exploitation."
organisation
BleepingComputer
A Google spokesperson was not immediately available for comment when BleepingComputer reached out for more details regarding the CVE-2025-48595 attacks and their targets.
infrastructure
Linux
Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.
organisation
Qualcomm
Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.
organisation
MediaTek
Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.
Google has released two sets of patches - 2026-06-01 and 2026-06-05 security patch levels - with the latter including all fixes from the first set, along with patches for kernel and third-party chipset components from Imagination Technologies, MediaTek, Qualcomm, and Unisoc.
organisation
Imagination Technologies
Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.
Google has released two sets of patches - 2026-06-01 and 2026-06-05 security patch levels - with the latter including all fixes from the first set, along with patches for kernel and third-party chipset components from Imagination Technologies, MediaTek, Qualcomm, and Unisoc.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Google)
organisation
CVE.org
"In multiple locations, there is a possible way to achieve code execution due to an integer overflow," according to a
description
of the vulnerability on CVE.org.
organisation
CVE-2025-48633
Google released patches for
two other high-severity zero-days
(CVE-2025-48633 and CVE-2025-48572) in December, and for another
zero-day flaw in a Qualcomm display component
(CVE-2026-21385) in March, all of which were tagged as "under limited, targeted exploitation.
organisation
CVE-2025-48572
Google released patches for
two other high-severity zero-days
(CVE-2025-48633 and CVE-2025-48572) in December, and for another
zero-day flaw in a Qualcomm display component
(CVE-2026-21385) in March, all of which were tagged as "under limited, targeted exploitation.
organisation
Google Pixel
While Google Pixel devices will receive these security updates immediately, other vendors will often take longer to test and tweak them for specific hardware configurations.
June 2026
Google released its June 2026 Android security updates to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
Click on any entity below to view its context and source!
infrastructure
Android
Google has released its
June 2026 Android security updates
, fixing 124 vulnerabilities across the mobile operating system.
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited.
Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
general_metric
124 Android flaws
Google has released its
June 2026 Android security updates
, fixing 124 vulnerabilities across the mobile operating system.
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited.
Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
organisation
Google
Google has released its
June 2026 Android security updates
, fixing 124 vulnerabilities across the mobile operating system.
organisation
Android Update
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited.
the month of June 2026
Threat actors exploited a high-severity flaw in the Framework component of Google's Android operating system.
Click on any entity below to view its context and source!
infrastructure
Android
Ravie Lakshmanan
Jun 02, 2026
Vulnerability / Mobile Security
Google on Monday
released
patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.
general_metric
124 Android flaws
Ravie Lakshmanan
Jun 02, 2026
Vulnerability / Mobile Security
Google on Monday
released
patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.
organisation
Vulnerability / Mobile Security
Ravie Lakshmanan
Jun 02, 2026
Vulnerability / Mobile Security
Google on Monday
released
patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.
general_metric
02 Jun
Ravie Lakshmanan
Jun 02, 2026
Vulnerability / Mobile Security
Google on Monday
released
patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.
June 5, 2026
Google released a June 2026 Android update that patched CVE-2025-48595, prompting the Federal Civilian Executive Branch to remediate vulnerabilities by June 5.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-48595
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
Federal Civilian Executive Branch
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
attribution
FCEB
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 2, 2026, added CVE-2025-48595 to its
Known Exploited Vulnerabilities (KEV) catalog
, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the flaw by June 5, 2026.
2026/06/05
Google issued two sets of patches for Android on June 5, 2026.
Click on any entity below to view its context and source!
infrastructure
Android
On Monday, Google issued two sets of patches: the
2026-06-01
and
2026-06-05
security patch levels, with the latter bundling all fixes from the first batch, along with patches for closed-source third-party and kernel subcomponents that may not apply to all Android devices.
Tactical Metrics
Metrics
infrastructure
Android
Affected Product
Click for context!
In previous Android cases, vulnerabilities carrying the same wording were later linked to
commercial spyware vendors
or state-sponsored operations targeting journalists, political figures, dissidents, executives, and government officials.
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices
Google fixed 124 Android flaws, including CVE-2025-48595, an actively exploited privilege escalation bug linked to targeted attacks.
According to Google and the Android Security Bulletin, the issue is caused by an integer overflow that can lead to code execution and privilege escalation on a vulnerable device.
Beyond CVE-2025-48595, Google patched a number of additional vulnerabilities in the Android System component, including flaws that could also result in privilege escalation.
Google Patches Actively Exploited Android Flaw Affecting Millions of Devices.
Google has released its
June 2026 Android security updates
, fixing 124 vulnerabilities across the mobile operating system.
The vulnerability affects devices running Android 14, 15, 16, and Android 16 QPR2.
The flaw is local, requires no user interaction, and resides inside the Android Framework, one of the most sensitive layers of the operating system.
The biggest challenge remains Android’s fragmented update model.
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited.
…2026
Vulnerability / Mobile Security
Google on Monday
released
patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has co…
The vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2 (Quarterly Platform Release 2).
Google fixes one actively exploited Android zero-day, 124 flaws.
Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
Local attackers can exploit the actively abused high-severity Android Framework vulnerability (tracked as CVE-2025-48595) to gain code execution and escalate privileges on devices running Android 14 or later.
"There are indications that CVE-2025-48595 may be under limited, targeted exploitation,"
the company said
on Monday in its March 2025 Android Security Bulletin.
"Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform.
We encourage all users to update to the latest version of Android where possible.
With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and elevate privileges on unpa…
…sets of patches: the
2026-06-01
and
2026-06-05
security patch levels, with the latter bundling all fixes from the first batch, along with patches for closed-source third-party and kernel subcomponents that may not apply to all Android devices.
"
Last month, Google also overhauled its Android and Chrome vulnerability rewards programs,
offering bounties of up to $1.5 million
for some Android exploits while scaling back payouts for flaws that are easier to find using artificial intellig…
Metrics
infrastructure
Linux
Affected Product
Devices receiving the latter will obtain all fixes included in the first release, plus updates for the Linux kernel and third-party chipset components from Qualcomm, MediaTek, Unisoc, and Imagination Technologies.
Intelligence Sources
The Hacker News
2026-06-02
BleepingComputer
2026-06-02
Google fixes one actively exploited Android zero-day, 124 flaws
BleepingComputer
Security Affairs
2026-06-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
CVE-2025-48595
entity
12x
timeline
Temporal Reference
June 2, 2026
date
5x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
4x
vulnerability
Exploited CVE
CVE-2025-48595
cve
2x
infrastructure
Affected Product
Android
software
2x
tactic
Cyber Operation Type
Privilege Escalation
tactic
Contextual Telemetry
Context Block
10 METRICS
industry
Targeted Sector
Government
sector
general metric
Android Flaws
124
android flaws
vulnerability
CVSS Score
8
score
general metric
Qpr2
16
qpr2
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Cvss Score
8
cvss score
general metric
Jun
2
jun
general metric
Patch Levels
2,026
patch levels
general metric
Critical Vulnerabilities
18
critical vulnerabilities
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.