• News/
  • bleepingcomputer-20260602111015

Google fixes one actively exploited Android zero-day, 124 flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 2, 2026
·
Updated

Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks. Local attackers can exploit the actively abused high-severity Android Framework vulnerability (tracked as CVE-2025-48595) to gain code execution and escalate privileges on devices running Android 14 or later. "There are indications that CVE-2025-48595 may be under limited, targeted exploitation," the company said on Monday in its March 2025 Android Security Bulletin. "Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform. We encourage all users to update to the latest version of Android where possible." While Google has yet to share technical details about the flaw or provide more information about the ongoing attacks targeting it, similar flaws have been exploited in the past by commercial spyware and by nation-state operations targeting high-profile or high-interest individuals. With this month's Android security updates, Google has fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components that attackers can abuse to trigger denial-of-service conditions and elevate privileges on unpatched Android devices. "The most severe of these issues is a critical security vulnerability in the Framework component that could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not ...

Read full article

Affected Software

2 affected components
Google Android Framework>=Android 14
Qualcomm Display component
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the release of June 2026 Android security patches by Google, addressing 124 vulnerabilities.

2

What security implications are discussed in the article?

The article highlights an actively exploited high-severity zero-day flaw in the Android Framework that allows local attackers to gain code execution.

3

What specific zero-day flaw is mentioned in the article?

The zero-day flaw mentioned is tracked as CVE-2025-48595, which is exploited in targeted attacks.

4

Which software components are affected by the vulnerabilities?

The Google Android Framework and Qualcomm Display component are the main software components affected.

5

How many total vulnerabilities were addressed in the June 2026 update?

Google addressed a total of 124 vulnerabilities in the June 2026 security update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203