Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisoryactively-exploited-vulnerabilityendpoint-software-vulnerabilityprivilege-escalation-method

Google Patches Android Zero-Day and High-Severity XR Privilege Escalation Flaws

Updated 3d agoFirst seen May 25, 202617 sources

Google has issued its June 2026 Android security updates to fix 113 vulnerabilities, including 18 critical flaws and a zero-day tracked as CVE-2025-48595 that the company said may be under limited, targeted exploitation. The zero-day affects the Android Framework and stems from an integer overflow memory-management issue that can enable code execution and potentially full device compromise. The update also addresses vulnerabilities in third-party components from Qualcomm, MediaTek, and Unisoc, and Google said devices running Android 10 or later can receive relevant fixes through Google Play services, with patch levels dated 2026-06-05 or later remediating the documented issues.

Google also published its June 2026 XR Security Bulletin, disclosing a high-severity flaw, CVE-2026-0072, in InputMethodManagerService. The bug is caused by a missing permission check in addInputMethodListener and can allow local elevation of privilege without additional execution privileges or user interaction; Google said it could also permit input text to be read without permission. The XR issue is fixed with security patch level 2026-06-01 or later, while full XR protection requires the broader Android June 2026 patch level as well, underscoring the need for enterprises to accelerate deployment of both platform and device-vendor updates.

Share:
Google Patches Android Zero-Day and High-Severity XR Privilege Escalation Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 2, 20265d ago

Google releases June 2026 Android security update for exploited zero-day

Google released an emergency Android security update addressing CVE-2025-48595, a critical Framework integer overflow flaw that it said may be under limited, targeted exploitation. The June 2026 bulletin fixed 113 vulnerabilities in total, including 18 critical issues, and noted that patch levels dated 2026-06-05 or later remediate the documented threats.

Android Zero-Day Flaw Exploited in the Wild

CISA adds Linux kernel CVE-2022-0492 to KEV

CISA added CVE-2022-0492, a Linux kernel cgroups v1 privilege-escalation flaw, to its Known Exploited Vulnerabilities catalog. The agency required covered federal agencies to remediate or discontinue affected software by 2026-06-05.

CISA warns of active attacks exploiting Android, Linux bugs

CISA adds CVE-2025-48595 to KEV and orders federal remediation

CISA added CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on 2026-06-02. The agency directed Federal Civilian Executive Branch agencies to remediate the Android flaw by 2026-06-05.

Google Patches Actively Exploited Android Flaw Affecting Millions of Devices
Jun 1, 20266d ago

Android discloses CVE-2026-0072 in June XR Security Bulletin

Google published the June 1, 2026 XR Security Bulletin identifying CVE-2026-0072, a high-severity elevation-of-privilege flaw in the XR component that could allow input text to be read without permission. Google said devices with security patch level 2026-06-01 or later address the XR bulletin issues.

Android Security Bulletin-June 2026 | Android Open Source Project
Apr 3, 20242y ago

Google warns of exploited Android zero-days affecting Pixel phones

Google disclosed that two Android zero-day vulnerabilities were being exploited and warned that Pixel devices were affected, with the activity linked to forensic companies. The report described the flaws as under active exploitation in the wild.

Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.