🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Google Android Framework Integer Overflow LPE Exploited (CVE-2025-48595) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 2, 2026
CVECVE-2025-48595
CVSS Score8.4
Affectedandroid
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:High
📋Executive Summary
Google's June 2026 Android security update patches 124 vulnerabilities across Android 14, 15, 16, and 16 QPR2, with CVE-2025-48595 confirmed under active exploitation. The flaw is a privilege escalation via integer overflow in the Android Framework component that requires zero user interaction and no elevated privileges to trigger, meaning an attacker can execute code on a target device silently. Google has acknowledged limited targeted exploitation, and the attack pattern matches commercial spyware deployment against specific individuals.
⚠️Why It Matters for MSSPs
Your technicians and client-side staff carry Android devices that authenticate into your RMM, PSA, and remote access platforms daily, and a zero-interaction privilege escalation on those devices is a direct path into your management stack without touching a single firewall rule. On the client side, any client employee running an unpatched Android device on corporate Wi-Fi or accessing company email and MFA apps is carrying a device that can be silently compromised, and if you have not told them that, you own that silence. The commercial spyware angle means this is not random spray-and-pray, it is targeted, which makes your higher-value clients and your own staff the realistic surface.
✅Recommended Action
Audit every Android device in your team's hands and any client-enrolled Android endpoints in your MDM within the next 24 hours, confirm the June 2026-06-05 patch level is applied or push an immediate enrollment compliance alert to flag unpatched devices, and send a direct client advisory today naming CVE-2025-48595, the zero-interaction risk, and the steps to check patch level on Android.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.