All CVEs View on NVD
CVE-2025-48595
HIGH8.4
CISA KEV
Published 2026-06-01 · Updated 2026-06-17 · Source security@android.com
Description
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-190
CISA Known-Exploited Vulnerability
Product: Android — Framework
Name: Android Framework Integer Overflow Vulnerability
Date added: 2026-06-02 · Due: 2026-06-05
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

