Google has released its June 2026 security update for the Android operating system, patching a total of 124 vulnerabilities. The most critical fix addresses CVE-2025-48595, a high-severity Elevation of Privilege (EoP) vulnerability in the Android Framework that is being actively exploited in the wild. Google has confirmed the flaw is subject to "limited, targeted exploitation." A successful attack could allow a malicious application to gain system-level privileges, completely compromising the security of the device. The update also includes patches for 18 other critical vulnerabilities. Due to the active exploitation, users are strongly advised to apply the June 2026 security patch as soon as their device manufacturer makes it available.
The primary vulnerability of concern is:
Google has not disclosed technical details about the vulnerability or the nature of the in-the-wild attacks to prevent wider exploitation. Such zero-day flaws are frequently used by commercial spyware vendors and nation-state actors for targeted surveillance.
The June 2026 bulletin also addresses several other critical flaws, including:
The update is being delivered in two patch levels:
Google Pixel devices are typically the first to receive these updates, with other manufacturers like Samsung, OnePlus, and others following over the subsequent weeks and months.
Active Exploitation Confirmed. Google's bulletin explicitly states there are "indications that CVE-2025-48595 may be under limited, targeted exploitation." This elevates the urgency of patching significantly. While the scope is described as "limited," any actively exploited zero-day poses a serious threat.
T1068 - Exploitation for Privilege Escalation: The core of the CVE-2025-48595 exploit, allowing a low-privilege app to gain higher system rights.T1404 - Execution through API: The malicious app would likely interact with a vulnerable API within the Android Framework to trigger the flaw.A successful exploit of CVE-2025-48595 could have severe consequences for an affected user. An attacker with system-level privileges can:
Given that the exploitation is targeted, the immediate risk to the general population is lower than a widespread attack. However, the existence of the exploit means it could be incorporated into more widely distributed malware in the future.
Detection on an individual mobile device is difficult for end-users. For enterprise mobile device management (MDM) platforms, the following patterns could indicate a compromise:
system or rootAndroid System Logs (logcat)Device running an outdated security patch levelFor most users, detection is not feasible. The focus should be on prevention and remediation.
Settings > System > System update (or similar path depending on the manufacturer) to check for and apply the update.New details emerge on Android's June 2026 update, clarifying CVE-2025-65018 as a critical, potentially wormable RCE, and listing additional CVEs.
The June 2026 Android security update now includes clarified details on CVE-2025-65018, identifying it as a critical Remote Code Execution (RCE) vulnerability in the Android Framework. This flaw is highlighted as potentially wormable, allowing remote attackers to execute arbitrary code without user interaction, significantly increasing its risk profile. Additionally, specific CVEs for other critical local privilege escalation flaws (e.g., CVE-2026-0043, CVE-2026-21352) and a Qualcomm memory corruption vulnerability (CVE-2026-21385) have been disclosed. The report also incorporates D3FEND and MITRE M1017 for enhanced detection and mitigation strategies.
CISA adds Android zero-day (CVE-2025-48595) to KEV catalog, mandating federal agency patching. New details reveal it's an integer overflow with CVSS 8.4.
The actively exploited Android zero-day, CVE-2025-48595, is now confirmed to be an integer overflow vulnerability in the Android Framework, carrying a high CVSS score of 8.4. This flaw allows for local privilege escalation without user interaction, affecting Android versions 14, 15, 16, and 16 QPR2. A significant development is CISA's addition of this CVE to its Known Exploited Vulnerabilities (KEV) catalog, which mandates federal agencies to patch by June 5, 2026. This highlights the critical nature and active threat posed by the vulnerability, reinforcing the urgency for all users to apply the June 2026 security update.
Google releases the June 2026 Android Security Bulletin, acknowledging active exploitation of CVE-2025-48595.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.