Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited

CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

ThreatVectr Newsdesk· 2 min read
Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited
Share

Google shipped the June 2026 Android security bulletin on Monday, closing 124 vulnerabilities across the OS. One is already being exploited.

The live bug is CVE-2025-48595, a high-severity privilege escalation in the Framework component. CVSS 8.4. No user interaction required, no additional execution privileges needed — an attacker who already has a foothold on the device can elevate to a higher-privileged context without the victim tapping anything.

Google's advisory describes the exploitation as "limited and targeted," the boilerplate the company uses when it has credible reporting of in-the-wild abuse but isn't naming victims. No attribution. No indicators. That's typical for Framework bugs that show up in commercial spyware chains, though Google hasn't said that's the case here.

The bulletin is split into the usual two patch levels. Devices reporting 2026-06-01 carry the Framework and System fixes, including CVE-2025-48595. The 2026-06-05 level rolls up vendor-specific patches for Arm, Imagination, MediaTek, and Qualcomm components. Pixel users get both in the same OTA. Everyone else is at the mercy of their OEM's release calendar, which remains the perennial weak link.

A few quick observations on the rest of the batch:

  • The Framework and System buckets account for the bulk of the high-severity entries, with several rated as remote code execution rather than EoP.
  • Qualcomm closed-source components contribute a sizable chunk of the vendor-side CVEs, consistent with prior months.

For defenders running MDM or EMM fleets, the operational steps haven't changed. Push the 2026-06-05 patch level as soon as your OEM publishes it. Confirm the level via ro.build.version.security_patch rather than trusting the carrier UI, which sometimes lags. If you're managing a BYOD population, treat any device stuck below 2026-06-01 as exposed to a known-exploited bug until proven otherwise.

Google did not credit an external researcher for CVE-2025-48595 in the public bulletin, which usually (though not always) signals an internal discovery via Threat Analysis Group or Project Zero telemetry. If a writeup surfaces, expect it to drop weeks after broad OEM rollout.

The full advisory and per-CVE severity table are on the Android Security Bulletin page. Pixel-specific fixes — which historically include a handful of additional Pixel-only CVEs — appear in the separate Pixel Update Bulletin.

Patch now. Worry about attribution later.

© 2026 Threat Vectr