A high-severity Android zero-day, CVE-2025-48595 (CVSS 8.4), is being actively exploited in targeted attacks — no user interaction required. Disclosed in Google's June 2026 Android Security Bulletin, the integer overflow in the Android Framework gives an attacker who already has code running on the device local privilege escalation, bypassing core security boundaries to reach sensitive system resources. Chained with other exploits, that becomes full device compromise.
Devices running Android 14, 15, 16 and 16 QPR2 are all affected. Patch level 2026-06-05 fixes the issue, and Google notified OEM partners over a month ahead of public disclosure. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 2.
Update immediately. Sideloaders face the highest risk, since third-party app channels are exactly how the attacker's code gets on the device in the first place.
Source: Cybersecurity News