CVE-2025-48595
Android Framework Integer Overflow Vulnerability
Description
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Description as published by the source, in English.
Key facts
- Published
- 2026-06-01
- Last modified
- 2026-07-22
- Assigned by
- security@android.com
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Probability of exploitation
-
1.7 %
higher than 75 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-02, with a remediation deadline of 2026-06-05 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Android | 14.0 | Affected | |
| Android | 15.0 | Affected | |
| Android | 16.0 | Affected |
Weakness type
-
CWE-190: Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is i…
References
- https://source.android.com/docs/security/bulletin/2026/2026-06-01
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595
Related at Berigo
Articles
-
Russian clusters bypass two step verification by asking for app passwords
Same product
2026-08-24
Google Threat Intelligence Group described three clusters linked to Russian intelligence on 20 August 2026, targeting academics, the defence industry…
-
A traveller gave a duress password at the border and was charged
Same product
2026-08-19
A United States citizen is charged with wiping the contents of his phone during a border search in January 2025. He pleaded not guilty, and the case …
-
Shared Claude conversations turned up in Google search
Same product
2026-08-18
On 27 July 2026 404 Media reported that shared Claude conversations and artifacts appeared in Google search results. The findings included medical re…
-
Approved partners get access to a model that finds unknown vulnerabilities
Same product
2026-08-12
OpenAI is expanding Daybreak with two access levels and releasing GPT-5.6-Cyber, a model trained for tasks such as finding zero-day vulnerabilities a…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.