CVE-2025-48595

Published Jun 1, 2026

Last updated 5 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48595 is an elevation of privilege vulnerability affecting the Android platform. This flaw allows an attacker to gain elevated access without requiring any additional execution privileges or user interaction for successful exploitation. Google has noted that there are indications of limited, targeted exploitation of CVE-2025-48595, making the June 2026 security patch, which addresses this vulnerability, particularly important.

Description
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source
security@android.com
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.4
Impact score
5.9
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-190

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

14

  1. June 2026 Android Security Bulletin notes CVE-2025-48595 is being exploited in the wild. It's being widely misreported in tech media as a 0-day vulnerability being exploited. That's a major misunderstanding of Android Security Bulletins and how poorly OEMs keep up with patches.

    @GrapheneOS

    2 Jun 2026

    273 Impressions

    1 Retweet

    11 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  2. June 2026 Android Security Bulletin notes CVE-2025-48595 is being exploited in the wild. It's being widely misreported in tech media as a 0-day vulnerability being exploited. That's a major misunderstanding of Android Security Bulletins and how poorly OEMs keep up with patches.

    @GrapheneOS

    2 Jun 2026

    131 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. June 2026 Android Security Bulletin notes CVE-2025-48595 is being exploited in the wild. It's being widely misreported in tech media as a 0-day vulnerability being exploited. That's a major misunderstanding of Android Security Bulletins and how poorly OEMs keep up with patches.

    @GrapheneOS

    2 Jun 2026

    562 Impressions

    3 Retweets

    22 Likes

    1 Bookmark

    1 Reply

    1 Quote

  4. Google's June 2026 Android update patches 124 flaws, including CVE-2025-48595, a zero-day exploited in targeted attacks on Android 14+ that can enable code execution and privilege escalation. #Android #ZeroDay #Qualcomm https://t.co/CSMXLKfRaW

    @TweetThreatNews

    2 Jun 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ ANDROID ZERO-DAY! Google has patched CVE-2025-48595, a privilege escalation flaw actively exploited in the wild. The fix is in the June 2026 security update, which patches 124 flaws total. Update your Android device NOW! #Android #ZeroDay #CyberSe... 🌐 cyber[.]netsecop

    @NetSecIO

    2 Jun 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities https://t.co/L1TGUm4hrH Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities app

    @f1tym1

    2 Jun 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. The nightmare for mobile security is live. Google’s June 2026 patch fixed 124 flaws, but an active Zero-Day (CVE-2025-48595) is being weaponized in targeted attacks.

    @DepthDesk

    2 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. 🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — June 02, 2026 1️⃣ GOOGLE PATCHES EXPLOITED ANDROID ZERO-DAY CVE-2025-48595 Google released its June 2026 Android Security Bulletin addressing 124 vulnerabilities, including a critical zero-day flaw (CVE-2025-48595) t

    @TraffAlex

    2 Jun 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 BREAKING: Google releases an Android update addressing CVE-2025-48595, a zero-day vulnerability exploited in targeted attacks, along with 123 other security fixes. Stay informed and update your devices. #NerdieNews #CyberSecurity #BreakingNews #InfoSec #ZeroDay #Google https

    @NewsNerdie

    2 Jun 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. "There are indications that CVE-2025-48595 may be under limited, targeted exploitation." https://t.co/SA8qON6lSn

    @ryanaraine

    2 Jun 2026

    338 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities: Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities… https://t.co/0sMXZrnfca h

    @shah_sheikh

    2 Jun 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Google fixes actively exploited Android vulnerability (CVE-2025-48595) https://t.co/b78SK7JBTu

    @TheCyberSecHub

    2 Jun 2026

    221 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Google fixes actively exploited Android vulnerability (CVE-2025-48595) - https://t.co/YIDfEMyRPp - @Google @Android @GooglePlay #CVE #SecurityUpdate #Vulnerability #Cybersecurity #CybersecurityNews https://t.co/6dN5GrzwxL

    @helpnetsecurity

    2 Jun 2026

    174 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Google fixes actively exploited #Android #vulnerability (#CVE-2025-48595) https://t.co/gz7xLZld1x https://t.co/6pzfvw3jGA

    @evanderburg

    2 Jun 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Google fixes actively exploited Android vulnerability (CVE-2025-48595): Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android… https://t.co/mKi8thcE7t https

    @shah_sheikh

    2 Jun 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Googleが悪用確認済みのAndroid脆弱性(CVE-2025-48595)を修正 https://t.co/sxqSRgH6nX

    @TYOBlackHatNews

    2 Jun 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Google's June 2026 Android Security Bulletin patches 124 vulnerabilities including a critical Framework flaw, CVE-2025-48595, flagged under active exploitation. The bug enables remote privilege escalation with no execution privileges and no user interaction required on Android

    @XavierRiveraX

    2 Jun 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Be Warned: Android 0-Day Vulnerability – CVE-2025-48595: Elevation of Privilege in Android Framework. Type: High-severity elevation-of-privilege (EoP) vulnerability. Affected Versions: Google Android versions 14 through 16-qpr2. https://t.co/SF8IEQGFbS

    @Notracktoday

    2 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Google rolls out an urgent Android security update to combat a zero day flaw under active attack. Ensure you update your device to secure against CVE-2025-48595 now!🔒 👉🏻 https://t.co/Et5K8Z2gzY #AndroidSecurity #ZeroDay #TechAlert

    @sqmagazine_news

    2 Jun 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 BREAKING: A critical zero-click, zero-day vulnerability in Android (CVE-2025-48595) is being actively exploited in the wild right now. No clicks, no downloads, just silent device takeover. Your phone might already be compromised. 🧵👇 https://t.co/1ThuP5nmaC

    @da7rkx0

    2 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. NEW THREAT INTEL: Android Framework 0-Day CVE-2025-48595 - zero-click privesc, actively exploited. 9 detections, 13 IOCs. https://t.co/KZvLJe0Sul #ThreatIntel #Android https://t.co/JkPV0seJxo

    @threadlinqs

    2 Jun 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Android Security Bulletin—June 2026 https://t.co/0gSqDJSkjR 18 crit vulns👀 CVE-2025-48595 exploited ITW

    @xvonfers

    2 Jun 2026

    4649 Impressions

    7 Retweets

    22 Likes

    15 Bookmarks

    1 Reply

    1 Quote

  23. Android June 2026 security update includes Google fixes, Samsung SMR patches, app updates and CVE-2025-48595 details. https://t.co/bY802wdxDk

    @malaysia601

    2 Jun 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 #Android Under Siege: #CVE-2025-48595 Zero-Day Exploitation Puts Hundreds of Millions of Devices at Immediate Risk + Video -Fact Checker: ✅: 2 ❌: 2 || 2/4 → Score: 50% ⚖️ -Prediction: 🟢 1 Positive | 🔴 0 Negative https://t.co/W25EFp6KNv

    @UndercodeNews

    2 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. We have just added an important vulnerability affecting Google Android (CVE-2025-48595) https://t.co/hdcxvjNBXo

    @vuldb

    2 Jun 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Andrordの月例更新が配信。ゼロデイ脆弱性CVE-2025-48595(複数個所における整数オーバーフロー)の修正が含まれている。修正脆弱性は113件で、うち18件は重大(Critical)。 https://t.co/flrQYGRN8o

    @__kokumoto

    2 Jun 2026

    623 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Googleが2026年6月のAndroidセキュリティアップデートを公開し、実際に悪用が確認されているゼロデイ脆弱性CVE-2025-48595を修正した。攻撃者による限定的な標的型攻撃で利用されている可能性があるとして、早急

    @yousukezan

    2 Jun 2026

    1544 Impressions

    3 Retweets

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.