{"schema_version":1,"title":"Google Android Framework vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in Google Android Framework: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-28580, was published on 1 June 2026.","url":"https://junglewise.ai/threats/technologies/android-framework","json_url":"https://junglewise.ai/threats/technologies/android-framework.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/android-framework","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":21,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":21},"latest":[{"cve":"CVE-2026-28580","cvss":7.8,"slug":"cve-2026-28580-google-android-framework-privilege-escalation-via-incorrect","title":"Google Android Framework privilege escalation via incorrect bounds check","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:25.013+00:00","url":"https://junglewise.ai/threats/cve-2026-28580-google-android-framework-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-28577","cvss":7.8,"slug":"cve-2026-28577-google-android-framework-tapjacking-in-windowmanagerservice","title":"Google Android Framework tapjacking in WindowManagerService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:24.82+00:00","url":"https://junglewise.ai/threats/cve-2026-28577-google-android-framework-tapjacking-in-windowmanagerservice"},{"cve":"CVE-2026-0100","cvss":7.8,"slug":"cve-2026-0100-google-android-framework-heap-buffer-overflow-in-loadedarsc-cpp","title":"Google Android Framework heap buffer overflow in LoadedArsc.cpp","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:23.73+00:00","url":"https://junglewise.ai/threats/cve-2026-0100-google-android-framework-heap-buffer-overflow-in-loadedarsc-cpp"},{"cve":"CVE-2026-0091","cvss":7.8,"slug":"cve-2026-0091-google-android-framework-privilege-escalation-in-launcher-process","title":"Google Android Framework privilege escalation in launcher process","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.737+00:00","url":"https://junglewise.ai/threats/cve-2026-0091-google-android-framework-privilege-escalation-in-launcher-process"},{"cve":"CVE-2026-0089","cvss":7.8,"slug":"cve-2026-0089-google-android-packageinstallerservice-privilege-escalation","title":"Google Android PackageInstallerService privilege escalation","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.64+00:00","url":"https://junglewise.ai/threats/cve-2026-0089-google-android-packageinstallerservice-privilege-escalation"},{"cve":"CVE-2026-0087","cvss":7.8,"slug":"cve-2026-0087-google-android-framework-privilege-escalation-in","title":"Google Android Framework privilege escalation in DomainVerificationService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.45+00:00","url":"https://junglewise.ai/threats/cve-2026-0087-google-android-framework-privilege-escalation-in"},{"cve":"CVE-2026-0076","cvss":7.8,"slug":"cve-2026-0076-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp","title":"Google Android Framework out of bounds read in ResourceTypes.cpp","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:21.747+00:00","url":"https://junglewise.ai/threats/cve-2026-0076-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp"},{"cve":"CVE-2026-0069","cvss":5.5,"slug":"cve-2026-0069-google-android-framework-resource-exhaustion-in-apkchecksums","title":"Google Android Framework resource exhaustion in ApkChecksums","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:21.363+00:00","url":"https://junglewise.ai/threats/cve-2026-0069-google-android-framework-resource-exhaustion-in-apkchecksums"},{"cve":"CVE-2026-0056","cvss":5.5,"slug":"cve-2026-0056-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp","title":"Google Android Framework out-of-bounds read in ResourceTypes.cpp","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:20.883+00:00","url":"https://junglewise.ai/threats/cve-2026-0056-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp"},{"cve":"CVE-2026-0055","cvss":0,"slug":"cve-2026-0055-google-android-path-traversal-in-packageinstallerservice","title":"Google Android path traversal in PackageInstallerService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:20.783+00:00","url":"https://junglewise.ai/threats/cve-2026-0055-google-android-path-traversal-in-packageinstallerservice"},{"cve":"CVE-2026-0048","cvss":7.8,"slug":"cve-2026-0048-google-android-tapjacking-in-windowstate-java","title":"Google Android tapjacking in WindowState.java","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:20.393+00:00","url":"https://junglewise.ai/threats/cve-2026-0048-google-android-tapjacking-in-windowstate-java"},{"cve":"CVE-2026-0018","cvss":5.5,"slug":"cve-2026-0018-google-android-framework-denial-of-service-in","title":"Google Android Framework denial of service in AccessibilityManagerService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:19.417+00:00","url":"https://junglewise.ai/threats/cve-2026-0018-google-android-framework-denial-of-service-in"},{"cve":"CVE-2026-0016","cvss":5.5,"slug":"cve-2026-0016-google-android-framework-permissions-bypass-in","title":"Google Android Framework permissions bypass in CredentialManagerService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:19.303+00:00","url":"https://junglewise.ai/threats/cve-2026-0016-google-android-framework-permissions-bypass-in"},{"cve":"CVE-2026-0009","cvss":7.8,"slug":"cve-2026-0009-google-android-framework-tapjacking-in-multiple-locations","title":"Google Android Framework tapjacking in multiple locations","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:19.173+00:00","url":"https://junglewise.ai/threats/cve-2026-0009-google-android-framework-tapjacking-in-multiple-locations"},{"cve":"CVE-2025-48652","cvss":7.8,"slug":"cve-2025-48652-google-android-framework-mdm-policy-bypass-in-installrepository","title":"Google Android Framework MDM policy bypass in InstallRepository.kt","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:19.05+00:00","url":"https://junglewise.ai/threats/cve-2025-48652-google-android-framework-mdm-policy-bypass-in-installrepository"},{"cve":"CVE-2025-48649","cvss":7.8,"slug":"cve-2025-48649-google-android-framework-permissions-bypass-in-multiple-locations","title":"Google Android Framework permissions bypass in multiple locations","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:18.947+00:00","url":"https://junglewise.ai/threats/cve-2025-48649-google-android-framework-permissions-bypass-in-multiple-locations"},{"cve":"CVE-2025-48595","cvss":7.8,"epss":0.0001,"slug":"cve-2025-48595-google-android-framework-privilege-escalation-via-integer","title":"Google Android Framework privilege escalation via integer overflow","severity":"critical","exploited":true,"published_at":"2026-06-01T22:16:18.093+00:00","url":"https://junglewise.ai/threats/cve-2025-48595-google-android-framework-privilege-escalation-via-integer"},{"cve":"CVE-2025-48570","cvss":7.8,"slug":"cve-2025-48570-google-android-framework-privilege-escalation-in-piptaskorganizer","title":"Google Android Framework privilege escalation in PipTaskOrganizer","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:17.827+00:00","url":"https://junglewise.ai/threats/cve-2025-48570-google-android-framework-privilege-escalation-in-piptaskorganizer"},{"cve":"CVE-2025-32348","cvss":7.8,"slug":"cve-2025-32348-google-android-framework-privilege-escalation-via-background","title":"Google Android Framework privilege escalation via background activity launch","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:17.72+00:00","url":"https://junglewise.ai/threats/cve-2025-32348-google-android-framework-privilege-escalation-via-background"},{"cve":"CVE-2025-22426","cvss":7.8,"slug":"cve-2025-22426-google-android-framework-privilege-escalation-in-computerengine","title":"Google Android Framework privilege escalation in ComputerEngine.java","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:17.51+00:00","url":"https://junglewise.ai/threats/cve-2025-22426-google-android-framework-privilege-escalation-in-computerengine"},{"cve":"CVE-2025-22424","cvss":0,"slug":"cve-2025-22424-google-android-framework-improper-input-validation-in-multiple","title":"Google Android Framework improper input validation in multiple locations","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:17.397+00:00","url":"https://junglewise.ai/threats/cve-2025-22424-google-android-framework-improper-input-validation-in-multiple"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Google Chrome","slug":"chrome","vulnerabilities":2530,"url":"https://junglewise.ai/threats/technologies/chrome"},{"name":"Google Android","slug":"android","vulnerabilities":359,"url":"https://junglewise.ai/threats/technologies/android"},{"name":"Google Chrome for iOS","slug":"chrome-for-ios","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/chrome-for-ios"},{"name":"Google Chromium V8","slug":"chromium-v8","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/chromium-v8"},{"name":"Google Chromium","slug":"chromium","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/chromium"},{"name":"Google TensorFlow","slug":"tensorflow","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/tensorflow"},{"name":"Google Cloud Platform","slug":"google-cloud-platform","vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/google-cloud-platform"},{"name":"Google Chrome for Android","slug":"chrome-for-android","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/chrome-for-android"},{"name":"Google ChromeOS","slug":"chromeos","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/chromeos"},{"name":"Google Pixel Bootloader","slug":"pixel-bootloader","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/pixel-bootloader"},{"name":"Google WebView","slug":"webview","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webview"},{"name":"Google A2ui\\","slug":"a2ui","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/a2ui"}],"technology":{"hub":true,"name":"Google Android Framework","slug":"android-framework","vendor":{"name":"Google","slug":"google","url":"https://junglewise.ai/threats/vendors/google"},"aliases":[],"category":"operating-system","homepage":"https://www.android.com/","repo_url":"https://android.googlesource.com/","description":"Android is an open-source operating system based on the Linux kernel, designed primarily for touchscreen mobile devices such as smartphones and tablets.","url":"https://junglewise.ai/threats/technologies/android-framework"},"most_severe":[{"cve":"CVE-2025-48595","cvss":7.8,"epss":0.0001,"slug":"cve-2025-48595-google-android-framework-privilege-escalation-via-integer","title":"Google Android Framework privilege escalation via integer overflow","severity":"critical","exploited":true,"published_at":"2026-06-01T22:16:18.093+00:00","url":"https://junglewise.ai/threats/cve-2025-48595-google-android-framework-privilege-escalation-via-integer"},{"cve":"CVE-2026-28580","cvss":7.8,"slug":"cve-2026-28580-google-android-framework-privilege-escalation-via-incorrect","title":"Google Android Framework privilege escalation via incorrect bounds check","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:25.013+00:00","url":"https://junglewise.ai/threats/cve-2026-28580-google-android-framework-privilege-escalation-via-incorrect"},{"cve":"CVE-2026-28577","cvss":7.8,"slug":"cve-2026-28577-google-android-framework-tapjacking-in-windowmanagerservice","title":"Google Android Framework tapjacking in WindowManagerService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:24.82+00:00","url":"https://junglewise.ai/threats/cve-2026-28577-google-android-framework-tapjacking-in-windowmanagerservice"},{"cve":"CVE-2026-0100","cvss":7.8,"slug":"cve-2026-0100-google-android-framework-heap-buffer-overflow-in-loadedarsc-cpp","title":"Google Android Framework heap buffer overflow in LoadedArsc.cpp","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:23.73+00:00","url":"https://junglewise.ai/threats/cve-2026-0100-google-android-framework-heap-buffer-overflow-in-loadedarsc-cpp"},{"cve":"CVE-2026-0091","cvss":7.8,"slug":"cve-2026-0091-google-android-framework-privilege-escalation-in-launcher-process","title":"Google Android Framework privilege escalation in launcher process","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.737+00:00","url":"https://junglewise.ai/threats/cve-2026-0091-google-android-framework-privilege-escalation-in-launcher-process"},{"cve":"CVE-2026-0089","cvss":7.8,"slug":"cve-2026-0089-google-android-packageinstallerservice-privilege-escalation","title":"Google Android PackageInstallerService privilege escalation","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.64+00:00","url":"https://junglewise.ai/threats/cve-2026-0089-google-android-packageinstallerservice-privilege-escalation"},{"cve":"CVE-2026-0087","cvss":7.8,"slug":"cve-2026-0087-google-android-framework-privilege-escalation-in","title":"Google Android Framework privilege escalation in DomainVerificationService","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:22.45+00:00","url":"https://junglewise.ai/threats/cve-2026-0087-google-android-framework-privilege-escalation-in"},{"cve":"CVE-2026-0076","cvss":7.8,"slug":"cve-2026-0076-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp","title":"Google Android Framework out of bounds read in ResourceTypes.cpp","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:21.747+00:00","url":"https://junglewise.ai/threats/cve-2026-0076-google-android-framework-out-of-bounds-read-in-resourcetypes-cpp"},{"cve":"CVE-2026-0048","cvss":7.8,"slug":"cve-2026-0048-google-android-tapjacking-in-windowstate-java","title":"Google Android tapjacking in WindowState.java","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:20.393+00:00","url":"https://junglewise.ai/threats/cve-2026-0048-google-android-tapjacking-in-windowstate-java"},{"cve":"CVE-2026-0009","cvss":7.8,"slug":"cve-2026-0009-google-android-framework-tapjacking-in-multiple-locations","title":"Google Android Framework tapjacking in multiple locations","severity":"info","exploited":false,"published_at":"2026-06-01T22:16:19.173+00:00","url":"https://junglewise.ai/threats/cve-2026-0009-google-android-framework-tapjacking-in-multiple-locations"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}