Junglewise Threat Intelligence

CVE-2025-48595: Google Android Framework privilege escalation via integer overflow

CVE-2025-48595 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-06-01

Technologies: Android Framework, Google Android Framework. Vendors: Android, Google.

Executive brief

A critical vulnerability in the Android Framework allows for unauthorized code execution on affected mobile devices. This flaw could enable a malicious application already on the device to gain elevated system privileges, potentially allowing it to access sensitive user data or interfere with core system operations. No user interaction is required for this exploit to occur, and it has been reported as being actively exploited in the wild.

Technical details

An integer overflow vulnerability exists in multiple locations within the Android Framework. The flaw allows a local attacker to achieve arbitrary code execution without requiring additional execution privileges or user interaction. By exploiting this memory safety issue, an attacker can escalate their privileges to a higher level (such as system or root). The vulnerability was disclosed in the June 2026 Android Security Bulletin and is confirmed to have been exploited in the wild. Security updates are typically delivered via the Android Open Source Project (AOSP) and device manufacturer patches.

Affected products

  • Google Android Framework

Timeline

  • 2026-06-01: advisory: Vulnerability included in Android Security Bulletin
  • 2026-06-02: disclosed: NVD publication date
  • 2026-06-02: exploited: Reported as exploited in the wild in the advisory summary

Related threats