CVE-2025-48595: Android Framework Integer Overflow Vulnerability
Added to the CISA Known Exploited Vulnerabilities catalog on 02 Jun 2026. Vendor: Android. Product: Framework.
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 05 Jun 2026)