Google patches 124 Android vulnerabilities including actively exploited zero-day (CVE-2025-48595)
By
BleepingComputer
Toasted golden, schmeared with insight. Top of the rack.
Summary
Google released the June 2026 Android Security Bulletin, patching 124 vulnerabilities including CVE-2025-48595, a zero-day flaw already under limited, targeted exploitation. The update addresses critical issues across Android System, Framework, and Qualcomm components. Google is urging users to apply the patches as soon as possible to mitigate active threats.
Key quotes
· 3 pulledGoogle has released the June 2026 Android security patches to fix 124 vulnerabilities, including CVE-2025-48595, a zero-day flaw that is being exploited in targeted attacks.
The update also addresses multiple critical issues across Android System, Framework, and Qualcomm components, with Google urging users to update as soon as possible.
CVE-2025-48595 is a zero-day flaw under limited, targeted exploitation.
You might also wanna read
Security researchers adapt Pixel 9 exploit chain to target Google Pixel 10
This article describes how security researchers adapted an exploit chain originally developed for the Google Pixel 9 to work on the Pixel 10
Apple patches critical iOS zero-day vulnerability exploited in targeted attacks
Apple has patched a critical zero-day vulnerability (CVE-2026-20700) affecting every iOS version since 1.0, discovered by Google's Threat An
Google Announces New Android Security Measures for 2026 Including Sideloading Restrictions and Advanced User Options
Google is implementing new security measures for Android in 2026 to combat malware, including restrictions on sideloading unverified apps. T
arstechnica.com·2mo agoGoogle Project Zero Addresses the 'Patch Gap' in Vulnerability Disclosure
The article discusses Google Project Zero's updated vulnerability disclosure policy, the '90+30' model, introduced in 2021 to accelerate pat
GrapheneOS patches Android VPN IP leak vulnerability that Google hasn't fixed
GrapheneOS has released an update fixing a recently disclosed Android VPN bypass vulnerability (affecting Android 16) that leaks users' real
CyberInsider·1mo agoCisco discloses actively exploited zero-day affecting up to 2 million IOS and IOS XE devices
Cisco disclosed an actively exploited zero-day vulnerability (CVE-2025-20352) affecting all supported versions of Cisco IOS and IOS XE, pote
arstechnica.com·8mo ago