CVE-2025-48595

Published Jun 1, 2026

Last updated 2 months ago

Exploit knownCVSS high 8.4
Android
ICS
Mobile device

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48595 is an elevation of privilege vulnerability affecting the Android platform. This flaw allows an attacker to gain elevated access without requiring any additional execution privileges or user interaction for successful exploitation. Google has noted that there are indications of limited, targeted exploitation of CVE-2025-48595, making the June 2026 security patch, which addresses this vulnerability, particularly important.

Description
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Analyzed
Products
android

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.9
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Android Framework Integer Overflow Vulnerability
Exploit added on
Jun 2, 2026
Exploit action due
Jun 5, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-190

Social media

Hype score
Not currently trending
  1. DEEP DIVE: CVE-2025-48595, an Android Framework integer overflow that lets an unprivileged app escalate to system-level code execution, no user interaction. Under limited, targeted exploitation and in CISA KEV. Affects Android 14, 15, and 16. https://t.co/iwCmchMqiz

    @DailyCVEBrief

    17 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🚨 Detailed Analysis for CVE-2025-48595 (SMA100 Buffer Overflow) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! 🔗 https://t.co/6RmFEUz9dY Critical Risk Identified! Affects Android. cc: @zoomeye_team (50.1k

    @darkeye_team

    29 Jun 2026

    138 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2025-48595: SMA100 Buffer Overflow Critical Vulnerability Alert! Android is affected by CVE-2025-48595. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/IvMxIdnHh3 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2025-48595" Search Dork:

    @zoomeye_team

    29 Jun 2026

    3312 Impressions

    4 Retweets

    42 Likes

    9 Bookmarks

    0 Replies

    1 Quote

  4. Every phone on Android 14, 15 or 16 is exposed to a flaw attackers are already using. Google $GOOGL fixed CVE-2025-48595 in its June update, an Android Framework bug that lets a malicious app escalate to deeper system control. CISA added it to its known-exploited list.

    @ShortInfoNews

    19 Jun 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. For the ones who missed it: Active Zero-Day (CVE-2025-48595) A critical zero-day vulnerability exists in the Android Framework affecting Android 14, 15, and 16, confirmed by Google to be under active exploitation as of June 2026. It's an elevation-of-privileges flaw that allows

    @devdoingsmth

    18 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Vulnérabilité Critique Google Android Framework : Escalade de Privilèges Activement Exploitée (CVE-2025-48595). #zoneantimalware

    @NicolasCoolman

    18 Jun 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Anyone on Android 14, 15 or 16 should install June's security update now. Google $GOOGL says CVE-2025-48595, a flaw in the Android framework, is already under targeted attack and lets a malicious app seize control of a phone with no user action. The update fixes 124 bugs.

    @ShortInfoNews

    18 Jun 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️ CVE-2025-48595: Desbordamiento de Entero en Android Framework con Escalada de Privilegios Local Análisis técnico de CVE-2025-48595, vulnerabilidad de integer overflow en Android Framework explotada activamente que permite escalada de privilegios local. https://t.co/XzeK

    @CiberPlanetaOrg

    18 Jun 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ Alerta de Seguridad: Desbordamiento de Enteros en Android Framework con Escalada Local de Privilegios (CVE-2025-48595) Vulnerabilidad de desbordamiento de enteros (CWE-190) en Android Framework permite ejecución de código y escalada local de privilegios (LPE). Explotaci

    @CiberPlanetaOrg

    18 Jun 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. [ICYMI] Satu aplikasi jahat bisa membuka pintu lebar-lebar bagi malware canggih, seperti pada CVE-2025-48595. Penyerang bisa menarget jurnalis dan aktivis. https://t.co/VFSaG08wzE

    @melekmedia

    17 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Google ha parcheado 124 vulnerabilidades en Android este mes de junio. Una de ellas ya estaba siendo explotada activamente cuando salió el boletín. Se llama CVE-2025-48595 y afecta al Framework de Android. No requiere ninguna interacción del usuario para escalar privilegios.

    @BurpWeb

    16 Jun 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 🚨 Your staff approves MFA into your RMM on #Android. #CVE-2025-48595 needs zero clicks to own that device. If you haven't told clients to patch today, you just inherited their breach. Audit your team's Android patch level in the next 4 hours. #mssp #zerocliclick https://t.co/X

    @bettermssp

    14 Jun 2026

    293 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CISA warns of active exploits targeting #Android and #Linux flaws (CVE-2025-48595 & CVE-2022-0492). The Android bug allows privilege escalation with zero user interaction! ⚠️ Visit @CISAcyber for more

    @DC3DCISE

    11 Jun 2026

    223 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. Google’s June Android bulletin fixed CVE-2025-48595, which may be under limited targeted exploitation. Push updates through MDM. https://t.co/H7pGGosrdk

    @InfosecDotWatch

    10 Jun 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. #Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities. #Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. - https://t.co/ppz3y41nVq @SecurityWeek

    @upgradeoptions

    10 Jun 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Top #CVE to prioritize 👀 - @Android Framework #privesc (CVE-2025-48595) - @SolarWinds Serv-U (CVE-2026-28318) - @Cisco Catalyst SD-WAN Manager (CVE-2026-20245) - @Cisco Unified Communications Manager (CVE-2026-20230) - @Acer Wave 7 routers (CVE-2026-49200/49201) - @UniFi OS

    @stansecure

    10 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🚨 Android just patched 124 security flaws. One of them — CVE-2025-48595 (CVSS 8.4) — may already be seeing limited targeted exploitation. No user interaction required. #Android 14, 15, 16, and 16 QPR2 affected. Read: https://t.co/vH9kudjPnH https://t.co/Cap4uir9WK

    @Dontbillme0

    9 Jun 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. #Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities. #Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. - https://t.co/ppz3y41VKY @SecurityWeek

    @upgradeoptions

    8 Jun 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Google patcht 124 Android-Schwachstellen inkl. Zero-Day. CVE-2025-48595 ermöglicht Code-Ausführung auf Android 14+. Sofortiges Update empfohlen. #AndroidSecurity #CVE #PatchNow https://t.co/M0XxgaiI8f

    @wall_your_x

    8 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 【AndroidとLinuxの既知脆弱性が実悪用、CISAが警告】 CISAが、Android FrameworkのCVE-2025-48595とLinux kernel cgroups v1のCVE-2022-0492について、実悪用を警告しています。 Android側は権限昇格、Linux側はコンテナ環境でのホスト

    @01ra66it

    7 Jun 2026

    198 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Google patched 124 Android flaws this week. CVE-2025-48595 (CVSS 8.4) gives root with no user interaction on Android 14-16 and is actively exploited. CISA's remediation deadline was yesterday. Update MDM policies now. #Google #CVE https://t.co/MtcOCtZNE5

    @FpeSre

    7 Jun 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🔴 #Google #Android, Integer Overflow Privilege Escalation, #CVE-2025-48595 (High) -DC-Jun2026-249 https://t.co/Q5aYgznQMZ

    @dailycve

    6 Jun 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. ⚠️ ANDROID ZERO-DAY! Google has patched CVE-2025-48595, a privilege escalation flaw actively exploited in the wild. The fix is in the June 2026 security update, which patches 124 flaws total. Update your Android device NOW! #Android #ZeroDay #CyberSe... 🌐 cyber[.]netsecop

    @NetSecIO

    6 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Top 5 Trending CVEs: 1 - CVE-2025-48595 2 - CVE-2026-28318 3 - CVE-2026-20245 4 - CVE-2018-17144 5 - CVE-2026-20230 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    6 Jun 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 Critical #Android Zero-Day (#CVE-2025-48595) Allows Silent Device Takeover—Patch Now! + Video https://t.co/3PnhC9HGOV Educational Purposes!

    @UndercodeUpdate

    6 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CISA KEV deadline hits TODAY: agencies must patch CVE-2025-48595 (Android Framework, CVSS 8.4) and CVE-2022-0492 (Linux cgroups priv-esc). Both actively exploited in targeted attacks. Check your mobile fleet and Linux hosts. #Cybersecurity #InfoSec #CISA

    @infrasecserv

    5 Jun 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Google’s June 2026 Android update patched 124 vulnerabilities. One of them is already being exploited. CVE-2025-48595 is an elevation-of-privilege flaw in the Android Framework affecting Android 14 through 16. Google confirms limited targeted exploitation is already underway.

    @ai_dev_official

    5 Jun 2026

    73 Impressions

    3 Retweets

    3 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  28. ⚠️ CISA has added Android Framework flaw CVE-2025-48595 to its KEV catalog after confirming active exploitation. The bug allows local privilege escalation, giving attackers system-level access on vulnerable devices. Patch Android devices ASAP. #Android https://t.co/UzOOKtOO

    @CyberEdition

    5 Jun 2026

    46 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  29. Android security just underwent a high-severity emergency patch cycle. Google’s June 2026 Security Bulletin addresses 124 vulnerabilities, headlined by an actively exploited zero-day (CVE-2025-48595) lurking inside the core Framework component.

    @handancorp

    5 Jun 2026

    56 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  30. Google、悪用中の Android ゼロデイ CVE-2025-48595 を修正 https://t.co/AaPiMkaYlc みなさんはふだん、更新通知とどう付き合っていますか。お使いの端末は、いまどのパッチレベルでしょうか。

    @innovaTopia_JP

    5 Jun 2026

    52 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 【AndroidとLinuxの実悪用脆弱性をCISAがKEV追加】 CISAがAndroid FrameworkのCVE-2025-48595と、Linux kernelのCVE-2022-0492をKnown Exploited Vulnerabilitiesに追加しました。 Android側は権限昇格に関係し、Googleも限定的な標的型悪用の可

    @01ra66it

    5 Jun 2026

    162 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Here is the rewritten post: Google's June 2026 Android update patched 124 vulnerabilities. One of them is already being exploited. CVE-2025-48595 is an elevation-of-privilege flaw in the Android Framework affecting Android 14 through 16. Google confirms limited targeted https:/

    @ai_dev_official

    4 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  33. CVE-2025-48595: Android Zero-Day Exploit Patched by Google https://t.co/iEiLIfpogJ #Cyberupdates #Cybertechnews #Cybersecurity

    @TheCyberDef

    4 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2025-48595: Android Zero-Day Exploit Patched by Google https://t.co/3jjOJnYriq #Cyberupdates #Cybertechnews #Cybersecurity

    @Vijaykiran0987

    4 Jun 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Google Patches Actively Exploited Android Flaw (CVE-2025-48595) Affecting Millions of Devices via @SecurityAffairs #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://t.co/AlbIGJ1asQ

    @proficioinc

    4 Jun 2026

    122 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Google’s June 2026 Android security update fixes 124 vulnerabilities, including a high-severity flaw (CVE-2025-48595) reportedly under limited active exploitation. Read More: https://t.co/rT1TccqCgM @Google @Android

    @spinidg

    4 Jun 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Google's June 2026 Android update patches 124 flaws including CVE-2025-48595, an integer overflow in the Framework component already under active exploitation. CISA added it to the KEV catalog with... Full analysis on our blog: https://t.co/ZwTJcEPs8b

    @FSEvolved

    4 Jun 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🛡️ CVE-2025-48595 Les patchs de sécurité de juin 2026 pour #Android ont été mis en ligne par #Google 🎯 Au total, ce ne sont pas moins de 124 vulnérabilités corrigées par la firme de Mountain View, dont une faille de #sécurité zero-day. #CVE https://t.co/BXWHw6

    @ITConnect_fr

    4 Jun 2026

    566 Impressions

    5 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. ⚠️ CRITICAL: Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited Google patched 124 Android vulnerabilities in June 2026, including CVE-2025-48595, a high-severity privilege escalation flaw (CVSS 8.4) in the Framework component that is actively https:

    @lenngrenm

    4 Jun 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 米当局CISAがAndroid・Linux・Mirasvitの脆弱性3件を「実際に悪用が確認された」カタログに新たに追加。早期対応を要求。 【注意喚起】米CISAがAndroid Framework(CVE-2025-48595)・Linuxカーネル(CVE-2022-0492)等3件を悪用

    @hasamayo1217

    4 Jun 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. ‼️ ثغره جديده من فئه zero-day على مستوى اندرويد اتسجل نشاط جديد لثغره اندرويد كان بيتم استخدامها بشكل محدود ومسجله برقم CVE-2025-48595 وبسبب اضافه framework جديد اتكون

    @hiddenlockT

    4 Jun 2026

    94 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  42. CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks https://t.co/QMqDiD0yib The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595, to its Known Ex

    @f1tym1

    4 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. CISA warns of active attacks exploiting Android, Linux bugs .. The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for

    @TheRabbitPy

    4 Jun 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  44. 米CISA、AndroidとLinuxの脆弱性が悪用されていると警告(CVE-2025-48595、CVE-2022-0492) | Codebook|Security News https://t.co/YRUiYdFcpI

    @ohhara_shiojiri

    4 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨米CISA、AndroidとLinuxの脆弱性が攻撃で悪用されていると警告(CVE-2025-48595、CVE-2022-0492) ⚠️バグハンターが再びマイクロソフトの脆弱性情報をリーク、同社の脆弱性開示対応に反発 〜サイバーアラート6月

    @MachinaRecord

    4 Jun 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Analyze the critical CVE-2025-48595 Android zero day flaw. Learn how this zero-click privilege escalation bug affects core devices and how to fix it. #AndroidSecurity #CVE202548595 #ZeroDay #MobileSecurity #InfoSec #ThreatIntel #AOSP https://t.co/xlWqC09iAa https://t.co/FvxXsAQP

    @Daily_CyberSec

    4 Jun 2026

    519 Impressions

    0 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  47. 🚨 HIGH SEVERITY: CVE-2025-48595 (CVSS 8.4) Integer overflow flaw enables local privilege escalation with code execution. No user interaction required. Affected: Multiple Android components Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/bbN0vazxzW

    @DFIR_Lab

    4 Jun 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 【Android 2026年6月更新、CVE-2025-48595に標的型悪用の可能性】 Androidの2026年6月セキュリティ情報では、複数のCriticalを含む多数の脆弱性が修正されています。GoogleはCVE-2025-48595について、限定的・標的型の悪用を

    @01ra66it

    3 Jun 2026

    307 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 【AndroidとLinuxの実悪用CVEにCISAが警告】 CISAが、Android FrameworkのCVE-2025-48595とLinux kernelのCVE-2022-0492について、実悪用を踏まえた警告を出しています。 Android側は権限昇格、Linux側はcgroups

    @01ra66it

    3 Jun 2026

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Google's June 2026 Android update patches 124 security flaws - including CVE-2025-48595 (CVSS 8.4), an actively exploited privilege escalation bug. CISA has added it to its KEV catalog. Update your Android device now! Credit: @TheHackersNews Follow @thecyberspec for more cyber

    @thecyberspec

    3 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations