LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-48595: Android Framework Integer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 2, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on Jun 2, 2026, with a federal patch deadline of Jun 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

This vulnerability is an integer overflow in the Android Framework that can result in local privilege escalation through code execution on affected devices. It matters because the flaw resides in core system components that run with elevated privileges, so successful local exploitation can expand an attacker's foothold without requiring remote access.

How it works

The weakness is categorized as CWE-190, an integer overflow or wraparound. In this class of flaw, arithmetic operations on integer values exceed the maximum representable value for the data type, producing an unexpected result such as an undersized buffer allocation or incorrect bounds check.

An attacker with the ability to supply crafted input to the affected code path can trigger the overflow. The resulting incorrect state may then be leveraged to execute arbitrary code at a higher privilege level on the device. Specific trigger conditions, affected code paths, and required attacker context must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects the Android Framework, the core set of libraries and services that underpin Android devices. Inventory begins with identifying managed Android endpoints through enterprise mobility management platforms, device management consoles, or asset inventories that record OS build fingerprints.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. The update addresses the integer-handling error in the framework components.

If you can't patch immediately

Until patches can be deployed, reduce exposure by applying mitigations described in the vendor advisory. Where mitigations are unavailable, discontinue use of the affected devices or isolate them from sensitive data and networks.

If your data may have been exposed

Local privilege-escalation vulnerabilities that are actively exploited can contribute to device compromise and subsequent data exposure. Organizations can run a free exposure scan of employee email addresses against known breach datasets to identify accounts that may already appear in public breach records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAndroid · Framework
WeaknessCWE-190
Added to CISA KEVJun 2, 2026
Federal patch deadlineJun 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities