Knox CVE Database
/
CVE-2025-48595
High
8.4

CVE-2025-48595: Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

Added to the CISA KEV catalog:
June 2, 2026

Overview

An integer overflow in the Android Framework affects Android 14, 15, and 16 (including the 16-QPR2 branch) across multiple code locations. A local attacker can trigger the overflow to corrupt memory and execute arbitrary code, escalating privileges on the device without needing any existing elevated permissions or victim interaction. The flaw is present in the Framework layer, meaning a malicious app or other local foothold is sufficient to reach it.

Vulnerability details

Affected vendor
Android
Affected product
Framework
Weakness type (CWE)
CWE-190

CWE-190 integer overflows occur when arithmetic on attacker-influenced values wraps around the bounds of the integer type, producing a result that is smaller than expected. In the Android Framework context, that incorrect result is then used in a subsequent memory operation, such as allocating a buffer sized by the wrapped value, which is too small to hold the actual data. The resulting out-of-bounds write gives an attacker the ability to corrupt adjacent memory structures and redirect execution. The advisory links associate the fix with platform/build/release and platform/external/sqlite, suggesting integer handling in SQLite or a related build component is involved, though the exact code path is not publicly confirmed.


An attacker with local access to the device, for example through a malicious application installed on the device, submits crafted data to the vulnerable Framework component. The integer overflow fires during processing of that data, producing an undersized allocation or an incorrect length value that is then used in a write operation. This corrupts memory in a way that allows the attacker to gain code execution at a higher privilege level than the originating process, achieving local privilege escalation. No additional permissions beyond app installation are required, and no user interaction beyond the initial installation is needed.

Severity and impact

8.4
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor device security patch levels against the June 2026 Android Security Bulletin (patch level 2026-06-05 or later). Devices running Android 14, 15, or 16 below that patch level are exposed and should be treated as unpatched.
  • Review Google Play Protect alerts and device management logs for Potentially Harmful Application (PHA) classifications on enrolled devices, particularly for apps installed from outside Google Play where Play Protect scanning coverage is reduced.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 5, 2026

Additional hardening

  • Apply the Android security update bringing the device to patch level 2026-06-05 or later, which addresses this vulnerability across Android 14, 15, and 16 including the 16-QPR2 branch.
  • Restrict sideloading on managed devices by enforcing policy that disallows installation from unknown sources, reducing the attacker's ability to place a malicious app that could reach the vulnerable Framework component.
  • Confirm Google Play Protect is active on all managed Android devices. Play Protect provides runtime scanning that can detect known malicious apps exploiting Framework-level flaws before or after a patch is applied.
  • For enterprise fleets, use a mobile device management platform to audit installed application sources and enforce minimum patch level compliance, prioritizing devices that cannot receive the June 2026 update promptly.

Key dates

Published (NVD)
June 1, 2026
Added to CISA KEV
June 2, 2026
Remediation deadline
June 5, 2026
Last updated
July 22, 2026

References

Frequently asked questions

Does CVE-2025-48595 affect my FedRAMP authorization?

If Android Framework runs inside your authorization boundary, CVE-2025-48595 affects your FedRAMP authorization directly. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 5, 2026 has already passed. An unpatched KEV inside the boundary is an assessor finding. An overdue one is visible to your assessor and sponsoring agency right now. Your path forward is remediation or formal documentation of the mitigation and the delay.

How does Knox help me handle CVE-2025-48595?

Knox does not patch Android Framework on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to execute. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that document the fix for your next assessment. The work of closing CVE-2025-48595 belongs to your team. Managing your compliance posture while you close it is not something you have to do alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2025-48595 class exposures. Gaps surface during ongoing monitoring rather than only when an assessor reviews your posture at a scheduled interval, giving your team earlier visibility and more time to act before a finding becomes a formal conversation.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2025-48595's remediation deadline of June 5, 2026 has passed. What happens now?

If CVE-2025-48595 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding and formally documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.