PT-2026-45567 · Google · Android

Published

2026-06-01

·

Updated

2026-06-06

·

CVE-2025-48595

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android 14 Android 15 Android 16 Android 16 QPR2
Description An integer overflow in multiple locations within the Android Framework allows for local escalation of privilege. This issue enables an attacker to achieve code execution at higher privileges without requiring additional execution privileges or any user interaction. There are indications that this flaw is being used in limited, targeted exploitation in the wild.
Recommendations Update Android 14, 15, 16, and 16 QPR2 to the 2026-06-05 security patch level.

Exploit

Fix

LPE

DoS

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-07652
CVE-2025-48595

Affected Products

Android