Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin — Threadlinqs Intelligence
As of 2026-06-02, Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-0655 · Severity: HIGH · CVSS: 8.4 · Status: ACTIVE · Category: VULNERABILITY
CVE-2025-48595 is a high-severity elevation-of-privilege flaw in the Android Framework caused by integer overflows in multiple code paths (CWE-190), allowing local privilege escalation with no
CVE-2025-48595 is a high-severity elevation-of-privilege (EoP) vulnerability in the Android Framework layer, disclosed in the June 2026 Android Security Bulletin and assigned the highest-severity Framework rating for that bulletin. NVD describes the root cause as an integer overflow (CWE-190): 'In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed.' The CVSS v3.1 base score is 8.4 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Exception to common reporting: although several trade outlets described the flaw as 'zero-click' and exploitable 'remotely,' the authoritative CVSS attack vector is Local (AV:L). The accurate reading is that CVE-2025-48595 is a local EoP primitive requiring no privileges (PR:N) and no user interaction (UI:N) — i.e., once an attacker has any low-privileged code-execution foothold on the device, this bug elevates them to higher (framework/system-context) privileges without further interaction. In real campaigns such a primitive is chained behind a separate remote initial-access exploit (for example a browser/renderer or messaging-client RCE delivered drive-by or zero-click), which is why the end-to-end chain is reported as remote and zero-click even though this specific CVE is a local privilege escalation. The integer overflow occurs in multiple locations within the Framework, meaning more than one reachable code path can trigger the unsafe arithmetic that leads to memory corruption and subsequent code execution in a higher-privileged context.
Integer-overflow EoP bugs in the Android Framework are valuable to advanced adversaries because the Framework (system_server and related system-context services exposed over Binder IPC) runs with elevated privileges and is reachable from unprivileged application sandboxes. An attacker app or compromised process supplies a crafted value (size/length/index) to an affected Framework code path; the value overflows during arithmetic (e.g., buffer-size or allocation calculation), producing an undersized allocation or out-of-bounds index that the attacker then leverages for controlled memory corruption and code execution at the privilege level of the Framework component. Because the bug needs 'no additional execution privileges,' it does not require any special permission grant, dangerous permission, or user consent dialog — a key property that makes it attractive for stealthy, fully-chained exploitation.
Google's bulletin notes: 'There are indications that CVE-2025-48595 may be under limited, targeted exploitation.' This phrasing is consistent with use by a well-resourced actor against specific targets rather than broad commodity abuse — the historical pattern for Android Framework/kernel 0-days is exploitation by commercial spyware vendors and nation-state operators for surveillance (audio/video/screen capture, message and credential theft, location tracking, and persistent access). No threat-actor attribution, malware family, hashes, domains, or IP IOCs were disclosed in the bulletin or the initial trade reporting; attribution is therefore Unknown with no public network/file indicators available for this CVE at time of analysis.
The issue is fixed at security patch level 2026-06-01 (the bulletin spans the 2026-06-01 and 2026-06-05 patch dates), with AOSP source patches expected to land in the Android Open Source Project repository shortly after publication. Google notifies Android partners of all bulletin issues at least a month before public disclosure, giving OEMs lead time to integrate fixes. Google Play Protect, enabled by default on devices with Google Mobile Services, provides partial mitigation by monitoring for and warning about potentially harmful applications, and is especially important for users who sideload apps from outside Google Play. Definitive remediation is applying a device security patch
Target sectors: government, media, civil society, technology, telecommunications
Target regions: Global
Timeline
- CVE-2025-48595 reserved with MITRE.
- Per Google policy, Android partners notified of all June 2026 bulletin issues at least a month before public disclosure (on/before this date).
- June 2026 Android Security Bulletin publicly discloses CVE-2025-48595 as a High-severity Framework EoP; fixed at security patch level 2026-06-01.
- Google states there are indications CVE-2025-48595 may be under limited, targeted exploitation.
- NVD publishes CVE-2025-48595 with CVSS v3.1 8.4 (HIGH, AV:L) and CWE-190 Integer Overflow root cause.
- Trade media (Cyber Security News, GBHackers) report active in-the-wild exploitation and full-device-compromise chaining; some describe the end-to-end chain as zero-click/remote.
- Second June 2026 bulletin security patch level (2026-06-05); AOSP source patches expected in the Android Open Source Project repository shortly after the bulletin.
Detections & IOCs
As of 2026-09-01, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-48595, T1588, T1189, T1203, T1068, T1211, T1212, T1082, T1543, T1005, T1113