ctipilot.ch

Android Framework integer-overflow LPE — actively exploited (limited/targeted), June 2026 bulletin

cve · CVE-2025-48595

Coverage timeline
1
first 2026-06-03 → last 2026-06-03
Briefs
1
1 distinct
Sources cited
36
24 hosts
Sections touched
1
trending_vulns
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-06-03CTI Daily Brief — 2026-06-03
    trending_vulnsFirst coverage — no-interaction LPE, 2026-06-05 patch level

Where this entity is cited

  • trending_vulns1

Source distribution

  • thehackernews.com5 (14%)
  • attack.mitre.org3 (8%)
  • welivesecurity.com3 (8%)
  • bleepingcomputer.com2 (6%)
  • helpnetsecurity.com2 (6%)
  • source.android.com2 (6%)
  • osservatorionessuno.org2 (6%)
  • blog.talosintelligence.com1 (3%)
  • other16 (44%)

External references

NVD · cve.org · CISA KEV

All cited sources (36)

Items in briefs about Android Framework integer-overflow LPE — actively exploited (limited/targeted), June 2026 bulletin (1)

CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation

From CTI Daily Brief — 2026-06-03 · published 2026-06-03 · view item permalink →

Google's June 2026 Android Security Bulletin patches CVE-2025-48595, a High-severity integer overflow in the Android Framework component that Google reports is under "limited, targeted exploitation" (Android Security Bulletin, 2026-06-01). The bug gives a local attacker — typically a malicious app already on the device — privilege escalation with no user interaction and no prior privileges, reaching system-level code execution across Android 14, 15, 16 and 16-QPR2 (BleepingComputer, 2026-06-02). The "limited, targeted" descriptor and the Framework location are, in our assessment, consistent with the historical pattern of commercial-spyware operators weaponising Framework LPEs against high-value targets — but no cited source attributes this specific case; the full fix requires reaching the 2026-06-05 patch level, which also carries chipset fixes from Qualcomm, MediaTek, Imagination and Unisoc (Android Security Bulletin, 2026-06-01). Defenders managing Android fleets: push the 2026-06-05 patch level via MDM/EMM and gate non-compliant devices via Security-Patch-Level compliance policy; disable sideloading and restrict installs to managed stores; this is doubly relevant for Swiss federal device fleets given the G7 Évian travel window (§ 1).

CVE Summary Table

A third actively-exploited CVE added to KEV this window — CVE-2022-0492, a Linux cgroup-v1 release_agent container escape — is covered in full in today's deep dive (§ 5).

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2024-21182 Oracle WebLogic Server, versions 12.2.1.4.0 / 14.1.1.0.0 7.5 high yes (2026-06-01) yes — unauth T3/IIOP Oracle CPU Jul 2024 THN
CVE-2025-48595 Android Framework (14/15/16/16-QPR2) High n/a yes (2026-06-02) yes — limited, targeted 2026-06-05 patch level Android Bulletin
CVE-2022-0492 Linux kernel cgroup v1 (< 5.17) 7.0 n/a yes (2026-06-02) yes — container escape kernel 5.17+ / distro backport CISA