In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References
| Link | Resource |
|---|---|
| https://source.android.com/docs/security/bulletin/2026/2026-06-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595 | US Government Resource |
Configurations
Configuration 1 (hide)
|
History
02 Jun 2026, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://source.android.com/docs/security/bulletin/2026/2026-06-01 - Vendor Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595 - US Government Resource | |
| CPE | cpe:2.3:o:google:android:16.0:-:*:*:*:*:*:* cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_2:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_3:*:*:*:*:*:* cpe:2.3:o:google:android:16.0:qpr2_beta_1:*:*:*:*:*:* cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:* |
|
| First Time |
Google android
|
02 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jun 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-190 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.4 |
01 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 22:16
Updated : 2026-06-02 20:19
NVD link : CVE-2025-48595
Mitre link : CVE-2025-48595
CVE.ORG link : CVE-2025-48595
JSON object : View
Products Affected
- android
CWE
CWE-190
Integer Overflow or Wraparound
