INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Google Patches Actively Exploited Android Flaw Affecting Millions

| 2026-06-03 09:44 CRITICAL HIGH EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The recent patching of a critical Android vulnerability, CVE-2025-48595, has sent shockwaves through the tech industry. This flaw, which affects devices running Android 14 to Android 16 QPR2, is already being exploited in targeted attacks by threat actors. The economics are very different from ransomware, with Google's patching of this issue resulting in millions of device updates across the mobile operating system. However, unlike traditional malware, this vulnerability requires no user interaction and resides within the Android Framework, a highly sensitive layer of the operating system. As a result, it is unlikely to be linked to specific threat actors or attributed to state-sponsored operations. The patching of this issue by Google has sent a strong message that security will not be compromised in exchange for profit, highlighting the importance of prioritizing cybersecurity in the tech industry.
Technical Mitigations AI-generated
* Implement a secure patching mechanism to ensure timely and effective fixes for identified vulnerabilities, such as the use of automated testing and validation tools. * Conduct thorough vulnerability assessments and penetration testing before deploying patches to identify potential exploitation vectors and mitigate risks. * Develop and implement robust incident response plans to quickly contain and remediate security incidents, including procedures for isolating affected devices and notifying stakeholders in a timely manner. * Regularly review and update patching strategies to ensure they remain effective against evolving threats, such as by incorporating new vulnerability detection tools and techniques into the patching process.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-48572CVE-2025-48572 CVE-2025-48595CVE-2025-48595 CVE-2025-48633CVE-2025-48633 CVE-2026-21385CVE-2026-21385
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎March 2025
Threat actors used a vulnerability in the Google Android operating system to target affected devices.
infrastructure Android
vulnerability CVE-2025-48595
organisation CVE-2025
‎2026/05/03
Threat actors exploited vulnerabilities in the Google Android operating system.
infrastructure Android
‎2026/06/01
Google released two sets of patches for the June 2026 Android update, with the latter bundling fixes from the first batch and targeting closed-source third-party and kernel subcomponents.
infrastructure Android
‎June 2, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on June 2, 2026, requiring Federal Civilian Executive Branch agencies to remediate the flaw by June 5, 2026.
vulnerability CVE-2025-48595
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎Jun 02, 2026
Threat actors exploited a previously unknown vulnerability in the Google June 2026 Android update.
‎2026/06/03
Google released patches for the CVE-2025-48595 vulnerability in June 2026, which affects devices running Android versions 14 and later.
infrastructure Android
organisation CVE-2025-48595
organisation Android System
organisation Google Patches Actively
organisation Google
organisation System
organisation Framework
organisation CVE-2025
organisation BleepingComputer
infrastructure Linux
organisation Qualcomm
organisation MediaTek
organisation Imagination Technologies
organisation SecurityAffairs
organisation CVE.org
organisation CVE-2025-48633
organisation CVE-2025-48572
organisation Google Pixel
‎June 2026
Google released its June 2026 Android security updates to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks.
infrastructure Android
general_metric 124 Android flaws
organisation Google
organisation Android Update
‎the month of June 2026
Threat actors exploited a high-severity flaw in the Framework component of Google's Android operating system.
infrastructure Android
general_metric 124 Android flaws
organisation Vulnerability / Mobile Security
general_metric 02  Jun
‎June 5, 2026
Google released a June 2026 Android update that patched CVE-2025-48595, prompting the Federal Civilian Executive Branch to remediate vulnerabilities by June 5.
vulnerability CVE-2025-48595
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎2026/06/05
Google issued two sets of patches for Android on June 5, 2026.
infrastructure Android
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources