{"id":514789,"date":"2026-06-02T14:20:14","date_gmt":"2026-06-02T14:20:14","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/514789\/"},"modified":"2026-06-02T14:20:14","modified_gmt":"2026-06-02T14:20:14","slug":"new-android-14-15-and-16-update-fixes-actively-exploited-security-flaw","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/514789\/","title":{"rendered":"New Android 14, 15 And 16 Update Fixes Actively Exploited Security Flaw"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/06\/1780410014_257_0x0.jpg\" alt=\"Google Android logo alongside Android banner.\" data-height=\"3416\" data-width=\"5125\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Google update patches against Android Zero-Day exploit.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Google\u2019s June 2026 Android security bulletin has been released, and it includes a fix for a zero-day vulnerability that it confirmed has been under \u201climited, targeted exploitation.\u201d Here\u2019s what users of Android 14, 15, 16 and 16 QPR2 need to know about CVE-2025-48595. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/06\/02\/dashlane-confirms-brute-force-password-attacks-targeting-some-users\/\" target=\"_blank\" aria-label=\"Dashlane Users Locked Out After Password Manager Detects Brute-Force Attack\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/06\/02\/dashlane-confirms-brute-force-password-attacks-targeting-some-users\/\" rel=\"nofollow noopener\">ForbesDashlane Users Locked Out After Password Manager Detects Brute-Force AttackBy Davey Winder<\/a>June Android Security Bulletin Confirms Fix For Actively Exploited CVE-2025-48595 Vulnerability<\/p>\n<p>With a massive global user base across multiple product lines, Google is a high-value target for cybercriminals and state-sponsored hackers alike. Which is why the company has a world-renowned security research unit in <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/16\/holy-grail-google-hackers-discover-pixel-10-zero-click-exploit-chain\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/16\/holy-grail-google-hackers-discover-pixel-10-zero-click-exploit-chain\/\" target=\"_self\" aria-label=\"Project Zero\" rel=\"nofollow noopener\">Project Zero<\/a> alongside <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/05\/google-to-pay-15-million-for-pixel-phone-security-exploit\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/05\/google-to-pay-15-million-for-pixel-phone-security-exploit\/\" target=\"_self\" aria-label=\"vulnerability reward platforms\" rel=\"nofollow noopener\">vulnerability reward platforms<\/a> for external bug hunters. While the latest Chrome security update fixed 151 vulnerabilities, none of them were being actively exploited in the wild. With the publication of the June 2026 Android security bulletin, however, Google has confirmed that a zero-day vulnerability, with a <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_self\" aria-label=\"Common Vulnerabilities and Exposures\" rel=\"nofollow noopener\">Common Vulnerabilities and Exposures<\/a> designation of CVE-2025-48595, has been subject to limited and targeted exploitation in the wild. Neither of those terms has been quantified, though, so it is currently unknown just how limited and targeted the attacks have been. <\/p>\n<p>What we do know is that this high-severity rated vulnerability, residing within the Android Framework itself, is an elevation-of-privileges type that could enable an attacker to potentially gain control of the impacted device. A CVE <a class=\"color-link\" href=\"https:\/\/feedly.com\/cve\/CVE-2025-48595\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/feedly.com\/cve\/CVE-2025-48595\" aria-label=\"threat intelligence report\">threat intelligence report<\/a> confirming this has stated that an \u201cunauthenticated local user can exploit an integer overflow to execute arbitrary code and escalate privileges to achieve full system compromise, including reading sensitive data, modifying files, and disrupting system availability.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/31\/151-chrome-security-flaws-22-critical-fixed-in-new-google-update\/\" target=\"_blank\" aria-label=\"151 Chrome Security Flaws, 22 Critical, Fixed In New Google Update\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/31\/151-chrome-security-flaws-22-critical-fixed-in-new-google-update\/\" rel=\"nofollow noopener\">Forbes151 Chrome Security Flaws, 22 Critical, Fixed In New Google UpdateBy Davey Winder<\/a><\/p>\n<p>Google has <a class=\"color-link\" href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-06-01\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-06-01\" aria-label=\"confirmed\">confirmed<\/a> that \u201cuser interaction is not needed for exploitation\u201d of this vulnerability. <\/p>\n<p>Because of the no-authentication-or-user-interaction-needed nature of this vulnerability, and the fact that it is already being exploited in the wild by attackers, users should apply the necessary Android security update from Google as soon as it is available for their device. Security patch levels of 2026-06-05 will ensure that your Android device is protected against the exploit of CVE-2025-48595, and you can check the status of yours by heading to About phone | Android version in the settings app. <\/p>\n","protected":false},"excerpt":{"rendered":"Google update patches against Android Zero-Day exploit. NurPhoto via Getty Images Google\u2019s June 2026 Android security bulletin has&hellip;\n","protected":false},"author":2,"featured_media":514790,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[257],"tags":[223038,67752,115746,223037,18,20095,19,17,223036,279,82,33828],"class_list":["post-514789","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-android-framework","tag-android-security-update","tag-android-zero-day","tag-cve-2025-48595","tag-eire","tag-google-android","tag-ie","tag-ireland","tag-june-android-security","tag-mobile","tag-technology","tag-zero-day"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116680958846373441","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/514789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=514789"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/514789\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/514790"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=514789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=514789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=514789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}