---
schema: 1
kind: vulnerability
title: "CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation"
headline: "CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation"
summary: "Google patches an actively-exploited, High-severity Android zero-day, CVE-2025-48595, in the June 2026 bulletin — an Android Framework integer overflow giving no-interaction local privilege escalation across Android 14/15/16; Google reports \"limited, targeted exploitation\" (a profile consistent with commercial-spyware use, though no source attributes this case). Full fix requires the 2026-06-05 patch level (Android Security Bulletin, 2026-06-01)."
discovered_at: "2026-06-03T05:00:03Z"
event_date: 2026-06-02
run_id: 2026-06-03-ee0eae61
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - zero-day
  - priv-esc
  - mobile
  - cisa-kev
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - defense
entities: []
cves:
  - id: CVE-2025-48595
    cvss: n/a
    epss: null
    type: priv-esc
    vector: local
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://source.android.com/docs/security/bulletin/2026/2026-06-01"
    publisher: Android Security Bulletin
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/"
    publisher: BleepingComputer
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/06/02/android-vulnerability-exploited-cve-2025-48595/"
    publisher: Help Net Security
    role: corroborating
closed_sources: []
evidence:
  - quote: "Google's June 2026 Android Security Bulletin patches CVE-2025-48595, a High-severity integer overflow in the Android Framework component that Google reports is under \"limited, targeted exploitation\" (Android Security Bulletin, 2026-06-01)."
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Push the Android 2026-06-05 patch level across MDM/EMM fleets and gate non-compliant devices** for CVE-2025-48595 (§ 2) — prioritise Swiss federal/cantonal devices given the G7 Évian travel window."
migrated_from: briefs/2026-06-03.md
---

Google's June 2026 Android Security Bulletin patches CVE-2025-48595, a High-severity integer overflow in the Android Framework component that Google reports is under "limited, targeted exploitation" ([Android Security Bulletin, 2026-06-01](https://source.android.com/docs/security/bulletin/2026/2026-06-01)). The bug gives a local attacker — typically a malicious app already on the device — privilege escalation with no user interaction and no prior privileges, reaching system-level code execution across Android 14, 15, 16 and 16-QPR2 ([BleepingComputer, 2026-06-02](https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/)). The "limited, targeted" descriptor and the Framework location are, in our assessment, consistent with the historical pattern of commercial-spyware operators weaponising Framework LPEs against high-value targets — but no cited source attributes this specific case; the full fix requires reaching the 2026-06-05 patch level, which also carries chipset fixes from Qualcomm, MediaTek, Imagination and Unisoc ([Android Security Bulletin, 2026-06-01](https://source.android.com/docs/security/bulletin/2026/2026-06-01)). Defenders managing Android fleets: push the 2026-06-05 patch level via MDM/EMM and gate non-compliant devices via Security-Patch-Level compliance policy; disable sideloading and restrict installs to managed stores; this is doubly relevant for Swiss federal device fleets given the G7 Évian travel window (§ 1).


#### CVE Summary Table

A third actively-exploited CVE added to KEV this window — **CVE-2022-0492**, a Linux cgroup-v1 `release_agent` container escape — is covered in full in today's deep dive (§ 5).

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2024-21182 | Oracle WebLogic Server, versions 12.2.1.4.0 / 14.1.1.0.0 | 7.5 | high | yes (2026-06-01) | yes — unauth T3/IIOP | Oracle CPU Jul 2024 | [THN](https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html) |
| CVE-2025-48595 | Android Framework (14/15/16/16-QPR2) | High | n/a | yes (2026-06-02) | yes — limited, targeted | 2026-06-05 patch level | [Android Bulletin](https://source.android.com/docs/security/bulletin/2026/2026-06-01) |
| CVE-2022-0492 | Linux kernel cgroup v1 (< 5.17) | 7.0 | n/a | yes (2026-06-02) | yes — container escape | kernel 5.17+ / distro backport | [CISA](https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog) |
