- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,677
The longer the fixing is set, the wider the window to attack.

In the operating system Android found a dangerous vulnerability, which is already used in real attacks. The main risk is that the owner of the smartphone can not press anything, do not download and do not notice the hack at all. To attack, a device is enough without a fresh security update to make such a breach enters for a hidden attack.
Google has uncovered a zero-day vulnerability in Android related to the Android Framework component. The problem received the identifier CVE-2025-48595 (8.4 on the CVSS 3.1 scale, AV:L/AC/C:L/C:L/I:C/H/A:H/A:H) and entered the June Android Security Bulletin published on 1 June 2026.
According to Google, vulnerability allows you to increase privileges on the device without any actions on the part of the user (zero-click). This feature makes the gap especially dangerous for targeted attacks, including for covert surveillance, installing spyware and data interception.
The company confirmed the signs of limited target operation CVE-2025-48595. This wording means that the attackers could already apply the vulnerability before the updates reached a wide audience. Google does not report a mass campaign, but the very fact of operation increases the risk for device owners without fresh updates.
Possible consequences depend on a specific attack and a model of the device. Successful operation can open access to sensitive information, system functions and help to gain a foothold in the OS. In the worst-case scenario, the attacker gets actual control of the smartphone.
Google has closed the problem in the Android security update with the level of 2026-06-05 and above. Device manufacturers have received information about the vulnerability at least a month before public disclosure to prepare and release fixes for their models.
The company separately indicates that multi-level Android protection reduces the likelihood of successful hacking. The ecosystem works to insulate applications, tools that prevent the use of vulnerabilities, and Google Play Protect. The service is included by default on devices with Google Mobile Services and warns of potentially dangerous programs, especially when installed from third-party sources.
Old smartphones, devices without support and models for which the manufacturer delays updates remain at risk. Earlier versions of Android may not have modern protective equipment, so similar attacks are more dangerous for them.
The Android team also plans to publish the source code of the Android Open Source Project (AOSP) repository within 48 hours of the release of the newsletter. The publication will help developers and manufacturers to quickly check the changes and close the gap in their assemblies.
Users should check the level of Android security updates and install the fresh version immediately after appearing. Companies should monitor the status of mobile devices, track strange activity and limit the installation of applications from unknown sources.

In the operating system Android found a dangerous vulnerability, which is already used in real attacks. The main risk is that the owner of the smartphone can not press anything, do not download and do not notice the hack at all. To attack, a device is enough without a fresh security update to make such a breach enters for a hidden attack.
Google has uncovered a zero-day vulnerability in Android related to the Android Framework component. The problem received the identifier CVE-2025-48595 (8.4 on the CVSS 3.1 scale, AV:L/AC/C:L/C:L/I:C/H/A:H/A:H) and entered the June Android Security Bulletin published on 1 June 2026.
According to Google, vulnerability allows you to increase privileges on the device without any actions on the part of the user (zero-click). This feature makes the gap especially dangerous for targeted attacks, including for covert surveillance, installing spyware and data interception.
The company confirmed the signs of limited target operation CVE-2025-48595. This wording means that the attackers could already apply the vulnerability before the updates reached a wide audience. Google does not report a mass campaign, but the very fact of operation increases the risk for device owners without fresh updates.
Possible consequences depend on a specific attack and a model of the device. Successful operation can open access to sensitive information, system functions and help to gain a foothold in the OS. In the worst-case scenario, the attacker gets actual control of the smartphone.
Google has closed the problem in the Android security update with the level of 2026-06-05 and above. Device manufacturers have received information about the vulnerability at least a month before public disclosure to prepare and release fixes for their models.
The company separately indicates that multi-level Android protection reduces the likelihood of successful hacking. The ecosystem works to insulate applications, tools that prevent the use of vulnerabilities, and Google Play Protect. The service is included by default on devices with Google Mobile Services and warns of potentially dangerous programs, especially when installed from third-party sources.
Old smartphones, devices without support and models for which the manufacturer delays updates remain at risk. Earlier versions of Android may not have modern protective equipment, so similar attacks are more dangerous for them.
The Android team also plans to publish the source code of the Android Open Source Project (AOSP) repository within 48 hours of the release of the newsletter. The publication will help developers and manufacturers to quickly check the changes and close the gap in their assemblies.
Users should check the level of Android security updates and install the fresh version immediately after appearing. Companies should monitor the status of mobile devices, track strange activity and limit the installation of applications from unknown sources.