Web_Logo
Remote Support
Security Alert: CISA Flags Android and Linux Vulnerabilities
Home » Security Alerts  »  Security Alert: CISA Flags Android and Linux Vulnerabilities

Security Alert: CISA Flags Android and Linux Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities list earlier this week, meaning both are confirmed to be actively targeted by attackers in the wild.

Inclusion on CISA's KEV catalog means these flaws are not theoretical — they are being used in real attacks right now.

  • CVE-2022-0492 — Linux Kernel Improper Authentication: A flaw in the Linux kernel that can allow an attacker to bypass security restrictions and gain elevated access. This affects businesses running Linux servers, cloud infrastructure, or network appliances with Linux-based firmware.
  • CVE-2025-48595 — Android Framework Integer Overflow: A vulnerability in the Android operating system that could allow a malicious application to escalate its privileges on the device. Affects Android smartphones and tablets, including those used for work.

Who is affected:

  • Businesses using Android devices for work — company-owned or BYOD — should ensure all devices are running the latest Android security patches.
  • Any Linux-based servers, NAS devices, or network appliances in your environment should be reviewed and updated promptly.

What to do:

  • On Android devices, check for updates under Settings > System > Software Update and install any available patches.
  • For Linux servers or appliances, apply current OS-level security patches through your standard update process.
  • US federal agencies have a deadline of 17 June 2026 to patch — given active exploitation, businesses should treat this with the same urgency.

If you are unsure whether your business has exposure to either of these vulnerabilities, speak with your IT provider. Source: CISA Known Exploited Vulnerabilities Catalog.