Google Confirms Limited Exploitation of an Android Framework Integer-Overflow Flaw, CVE-2025-48595, in June Security Bulletin
Google's June 2026 Android update patches a Framework privilege-escalation zero-day under limited, targeted exploitation. CISA added it to the KEV catalog with a June 5 federal deadline.
Overview
Google’s June 2026 Android security update patches a vulnerability in the Android Framework, tracked as CVE-2025-48595, that the company says may be under active exploitation. Google’s bulletin states that “there are indications that CVE-2025-48595 may be under limited, targeted exploitation,” according to BleepingComputer. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on June 2, 2026, with a remediation due date of June 5, 2026, per the CISA KEV catalog.
What We Know
CVE-2025-48595 is a privilege-escalation flaw in the Android Framework. The National Vulnerability Database describes it as follows: “In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.” The NVD assigns a CVSS base score of 8.4 (High) with the vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and classifies the weakness as CWE-190, the identifier for an integer overflow or wraparound.
The AV:L portion of that vector indicates a local attack vector: an attacker needs code already running on the device before the flaw can be used to climb to higher privilege. According to BleepingComputer, the high-severity flaw lets local attackers gain code execution and escalate privileges on devices running Android 14 or later, with no user interaction needed. Help Net Security reports that the vulnerability is being exploited via a malicious app that targeted users have been tricked into installing, and describes the affected component, the Android Framework, as a set of APIs and system services that apps interact with directly.
The flaw affects Android versions 14, 15, 16, and 16-qpr2 (Quarterly Platform Release 2), according to Help Net Security. CISA’s catalog entry summarizes the issue as an integer overflow “that allows for code execution that could allow for local privilege escalation,” and lists its known ransomware campaign use as Unknown, according to the CISA KEV catalog.
CVE-2025-48595 is one of 124 vulnerabilities addressed in the June 2026 update, 18 of which are rated critical across System, Framework, and Qualcomm components, according to BleepingComputer. The update ships two security patch levels, 2026-06-01 and 2026-06-05, with the later level including all the earlier fixes plus third-party and kernel patches, per the same outlet.
Federal Remediation Requirement
The KEV listing carries weight beyond individual Android device owners. Federal civilian agencies are bound by Binding Operational Directive 22-01 to remediate listed vulnerabilities by the catalog’s due date. CISA’s required action for CVE-2025-48595 reads: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable,” according to the CISA KEV catalog. With a June 2 add date and a June 5 due date, agencies were given three days to act.
The phrase Google uses, “limited, targeted exploitation,” is the wording the company typically reserves for cases where a small number of high-value targets are being attacked rather than for mass-market campaigns. The cited reporting does not name the actors involved or the targets.
This is not the first Android security update of 2026 to ship a fix for an actively exploited flaw. In March, Google patched a Qualcomm display-subsystem zero-day exploited in targeted Android attacks, as previously reported. CVE-2025-48595 differs in that it sits in the Android Framework itself rather than a chipset vendor’s component, meaning it is not confined to a particular hardware platform.
What We Don’t Know
The cited reporting does not disclose who is exploiting CVE-2025-48595, against whom, or for how long the flaw was used before the patch. It also does not detail the technical chain an attacker would need to first run code on the device, which the local attack vector requires. How quickly hardware makers will push the June patch level downstream to their own update channels is not addressed in the cited sources.
It is also unclear from the public record whether the in-the-wild exploitation traces to commercial spyware vendors, criminal operators, or state-aligned actors. Google’s standard “limited, targeted” language is consistent with several of those possibilities and does not, on its own, single out any one of them.