CVE-2025-48595 is a high-severity integer overflow vulnerability (CVSS 8.4) in the Android Framework that allows local privilege escalation to gain complete device access.
Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-48595 is an integer overflow vulnerability in the Android Framework, a set of APIs and system services that apps interact with directly. The flaw allows attackers to escalate privileges on a vulnerable device, and they may gain complete access to the device … More → The post Google fixes actively exploited Android vulnerability (CVE-2025-48595) appeared first on Help Net Security .