Web_Logo
Remote Support
Security Alert: Android Flaw Under Active Exploitation
Home » Security Alerts  »  Security Alert: Android Flaw Under Active Exploitation

Security Alert: Android Flaw Under Active Exploitation

A security flaw in Android (versions 14 through 16) is being actively exploited in targeted attacks, and has been added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog.

  • What it is: CVE-2025-48595 — an integer overflow flaw in the Android framework that allows attackers to execute code and escalate privileges on an affected device.
  • Who is affected: Any business device running Android 14, 15, or 16 — including smartphones and tablets used for work email, files, or business applications.
  • What the risk is: Successful exploitation could give an attacker control over the affected device, including access to corporate email, cloud storage, and business apps.
  • What action is needed: Ensure all Android business devices have the latest June 2026 security update applied. If your organisation manages devices through an MDM solution, verify patch compliance across the fleet now.

We recommend checking for and applying pending software updates on all Android devices as soon as possible. For reference, CISA’s Known Exploited Vulnerabilities catalog is available at cisa.gov.