Web_Logo
Remote Support
Security Alert: Android and Linux Vulnerabilities Under Active Attack
Home » Security Alerts  »  Security Alert: Android and Linux Vulnerabilities Under Active Attack

Security Alert: Android and Linux Vulnerabilities Under Active Attack

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog this week, confirming both are being actively exploited in the wild. Businesses using Android devices or Linux-based systems should act promptly.

  • What it is: CISA has flagged CVE-2025-48595, an integer overflow vulnerability in the Android Framework that can allow attackers to escalate privileges on affected Android devices, and CVE-2022-0492, an improper authentication vulnerability in the Linux Kernel that threat actors continue to exploit in real-world attacks.
  • Who is affected: Any business using Android smartphones, tablets, or other Android devices for work purposes. Also any organisation running Linux-based systems, including servers and network appliances.
  • What the risk is: Exploitation can allow attackers to gain elevated access to affected devices, potentially leading to data theft or full system compromise. CISA only adds vulnerabilities to this list when active exploitation has been confirmed.
  • What action is needed: Apply Android security updates immediately on all business Android devices — typically available via Settings > Software Update. Ensure any Linux servers or systems are running the latest kernel patches. If devices are managed through an MDM platform, verify that updates have been pushed and applied. Source: CISA Advisory, 2 June 2026.

We recommend reviewing device update status across all business Android devices this week. If you are unsure whether your devices are current, contact your IT provider to confirm.