Google fixes Android phone flaw under attack in June update: CVE-2025-48595 hits Android 14 through 16, 124 bugs patched, hundreds of millions of devices
Anyone running Android 14, 15 or 16 should install the June security update now. Google $GOOGL says CVE-2025-48595, a flaw in the Android framework, is already under targeted attack and lets a malicious app take control of a phone with no user action. It fixes 124 bugs.
Google $GOOGL has released its June 2026 security update for Android, and this is one users should not put off installing. The update addresses 124 separate vulnerabilities, including one that attackers are already exploiting. The actively exploited flaw, tracked as CVE-2025-48595, sits in the core Android framework and affects devices running Android 14, 15 and 16. It is a privilege-escalation bug with a severity score of 8.4, meaning a successful attacker can lift an ordinary app's permissions to a much higher level and potentially gain control over core device functions. What makes it dangerous is that it requires no interaction from the user. Google describes the flaw as being under limited, targeted exploitation, the language the company uses when it has confirmed real-world attacks rather than only theoretical risk. Because the attack runs locally, analysts believe it is most likely delivered through a malicious app that people are persuaded to install. Of the 124 fixes in this release, 18 are rated critical. The 2026-06-01 patch level covers the core operating system, while the later 2026-06-05 level adds fixes for kernel components and chipset drivers from suppliers such as Qualcomm and MediaTek. (Sources: Google Android Security Bulletin, BleepingComputer, Help Net Security)