Status: KEV
| Advisory ID: CVE-2025-48595
Key Details
| CVE | CVE-2025-48595 |
| Vulnerability Name | Android Framework Integer Overflow Vulnerability |
| Affected products | Android Framework |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-190 (Integer Overflow or Wraparound) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-06-02. |
| Exploitation prediction (EPSS) | 1.71% probability of exploitation in the next 30 days (76% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-06-05 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
What to Do
Monitor Android's web page for any future patch releases.
References
KEV Required Action