CVE-2025-48595

Android · Framework

An integer overflow in the Android Framework allows a local, unprivileged app to escalate privileges and run code in a privileged context. Google reports limited, targeted exploitation, and it is listed in the CISA KEV catalog.

Executive summary

A local privilege-escalation flaw in the Android Framework (CVSS 8.4, integer overflow) is under limited, targeted exploitation in the wild and is in CISA KEV. It lets an unprivileged on-device app gain elevated code execution with no user interaction. Update affected devices to the 2026-06-01 security patch level or later.

Vulnerability

An integer overflow "in multiple locations" within the Android Framework leads to memory corruption and code execution. Per NVD it is a local vector (CVSS 8.4 HIGH, AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): an attacker who can run unprivileged code on the device, typically a malicious or compromised app, triggers the overflow to escalate into the Framework's privileged context. No additional execution privileges and no user interaction are required.

Business impact

Rated CVSS 8.4 (HIGH); Google rates it High severity. This is not a remote-over-the-network flaw. It is a local escalation primitive, and its danger is as the second stage of an exploit chain: an app or a remote bug lands initial code execution, then this flaw escalates to system-level control. Google's note of limited, targeted exploitation and the CISA KEV listing point to use in targeted intrusions (the pattern typical of mercenary spyware), where the payoff is full device compromise: data theft, surveillance of microphone, camera, location, and messages, and persistence that survives normal use.

Remediation

Immediate Action: Update affected devices to the 2026-06-01 Android security patch level or later. Check the current level under Settings, then About phone, then Android security update. Managed fleets should push the June 2026 (or later) OEM update and enforce a minimum patch level.

Proactive Monitoring: Use MDM/EMM patch-level compliance reporting to find devices below 2026-06-01, and Mobile Threat Defense to flag anomalous app behavior. Traditional network or host IDS rules do not apply to an on-device Android EoP.

Compensating Controls: Keep Google Play Protect enabled, avoid sideloading and untrusted third-party app stores, and remove unused apps to shrink the local attack surface while OEM patches roll out.

Exploitation status

Public Exploit Available: No public PoC observed in our exploit index, but active in-the-wild exploitation is confirmed (Google reports limited, targeted exploitation; CISA KEV added 2026-06-02).

Analyst recommendation

Prioritize this on any managed Android fleet: enforce the 2026-06-01 (or later) security patch level and quarantine devices that cannot update. Because exploitation is targeted rather than mass-scale, high-risk users such as executives and journalists should be updated first.