Android June 2026 update patches actively exploited zero-day (CVE-2025-48595)
Google's June 2026 Android security update fixes 124 vulnerabilities, including CVE-2025-48595, an integer overflow in the Android Framework already under limited, targeted exploitation. The flaw lets attackers escalate privileges on a device with no user interaction and affects Android 14, 15 and 16. CISA added it to its Known Exploited Vulnerabilities list with a June 5 federal patch deadline.
Google's June 2026 Android update patches 124 flaws, 18 critical. The actively exploited zero-day CVE-2025-48595 is an integer overflow in the Android Framework enabling silent privilege escalation. Google describes limited, targeted exploitation, a pattern tied to commercial spyware and state-backed actors. Affects Android 14, 15 and 16. CISA KEV listing June 2, federal deadline June 5. Fix ships in the June 5 patch level.