• News/
  • bleepingcomputer-20260603153616

CISA warns of active attacks exploiting Android, Linux bugs

BleepingComputer
·
Bill Toulas
·
Published Jun 3, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. The most recent flaw the agency added to its Known Exploited Vulnerabilities (KEV) catalog, CVE-2025-48595, is a high-severity integer overflow vulnerability in the Android Framework, which can be leveraged for increased privileges. According to Google’s recent security bulletin, the security issue impacts Android 14 through 16, and requires no user interaction to exploit. Google indicated that CVE-2025-48595 may be under limited targeted exploitation in the wild, but provided no specific details about the activity or technical information about the flaw or the incidents. The issue has been addressed with the release of June 2026 security patches (2026-06-01 and 2026-06-05 security patch levels). The second vulnerability CISA added to KEV is tracked as CVE-2022-0492, a high-severity privilege escalation flaw that impacts multiple Linux kernel branches, from 2.6 through 4.20, and from 5.5 through 5.17. The flaw lies in the ‘cgroup_release_agent_write()’ function of the cgroups v1 subsystem, which, due to insufficient authentication checks, can be abused by a local attacker to bypass namespace isolation, escalate privileges, and potentially escape from a container to gain root-level access on the host system. According to past reports from Aqua Security and Palo Alto Networks, the issue primarily impacts conta...

Read full article

Affected Software

2 affected components
Google Android Framework>=14<=16
Linux Kernel>=2.6<=4.20, >=5.5<=5.17

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's warning about active attacks exploiting vulnerabilities in the Linux kernel and Android operating system.

2

What vulnerabilities are being exploited according to CISA?

CISA is highlighting vulnerabilities in the Linux kernel and the Android operating system, specifically mentioning CVE-2025-48595.

3

What severity level is the newly added CVE-2025-48595 flaw?

CVE-2025-48595 is categorized as a high-severity vulnerability.

4

Which products are specifically mentioned as affected by these vulnerabilities?

The affected products include the Google Android Framework and the Linux Kernel.

5

What action does CISA recommend in response to these vulnerabilities?

CISA recommends that users and organizations apply relevant updates and patches to protect against these vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203