Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
August 4, 2026
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
Home/CyberSecurity News/Critical Android 0-Day CVE-2023-35674 Lets Attackers Control Devices
CyberSecurity News

Critical Android 0-Day CVE-2023-35674 Lets Attackers Control Devices

Key Takeaways A critical zero-day vulnerability, CVE-2025-48595, affecting Android devices is currently under active exploitation in targeted attacks. The flaw allows attackers to achieve elevation...

Emy Elsamnoudy
Emy Elsamnoudy
June 2, 2026 3 Min Read
52 0

Key Takeaways

  • A critical zero-day vulnerability, CVE-2025-48595, affecting Android devices is currently under active exploitation in targeted attacks.
  • The flaw allows attackers to achieve elevation of privilege without any user interaction, potentially leading to full device compromise.
  • Android versions 14, 15, 16, and 16 QPR2 are impacted.
  • Google has released patches in the June 2026 Android Security Bulletin (patch level 2026-06-05), urging immediate updates.

Android Zero-Day Under Active Exploitation

A severe zero-day vulnerability within the Android operating system is being actively exploited, allowing attackers to gain significant control over compromised devices. The flaw, identified as CVE-2025-48595, was detailed in Google’s June 2026 Android Security Bulletin, where the company confirmed its limited real-world exploitation in targeted campaigns.

Table Of Content

  • Key Takeaways
  • Android Zero-Day Under Active Exploitation
  • Exploitation and Impact
  • What You Should Do

The vulnerability resides within the Android Framework component. Classified as a high-severity elevation-of-privilege (EoP) issue, it poses a substantial risk due to its exploitation characteristics. Under specific conditions, threat actors can leverage this flaw remotely to escalate privileges without requiring any user interaction or additional execution permissions.

Security researchers highlight that this vulnerability impacts devices running Android versions 14, 15, 16, and 16 QPR2. The absence of user interaction during exploitation significantly elevates its danger, especially in sophisticated, targeted attack scenarios.

Exploitation and Impact

In practical attack chains, vulnerabilities like CVE-2025-48595 are frequently combined with other exploits to achieve comprehensive device compromise. Such compromises can encompass data exfiltration, sustained surveillance, and persistent access to the device. Google’s bulletin underscores the gravity of the most severe issues addressed, noting their potential to result in remote privilege escalation without user involvement, particularly if platform-level mitigations are bypassed.

Despite Android’s robust multi-layered security architecture, which includes sandboxing, stringent permission controls, and runtime protections, advanced attackers can still exploit such flaws under specific conditions, particularly on devices that are unpatched or running outdated software.

Google confirmed that its Android partners were informed of the vulnerability at least one month prior to public disclosure. This lead time allowed Original Equipment Manufacturers (OEMs) to prepare and distribute necessary patches to their respective device ecosystems.

The security updates included in patch level 2026-06-05 fully remediate CVE-2025-48595 and related vulnerabilities. Source code patches are anticipated to be released to the Android Open Source Project (AOSP) repository shortly after the bulletin’s publication.

Google Play Protect plays a crucial role in mitigating exploitation attempts. Enabled by default on devices with Google Mobile Services, it actively scans applications and alerts users to potentially harmful software. However, users who opt to sideload applications from third-party sources face an elevated risk, as these channels are often exploited to deliver malicious payloads.

The Android Security Team has issued a strong recommendation for all users and organizations to update their devices immediately to the latest available security patch level. The delay in patch adoption remains a primary enabler for threat actors to weaponize known vulnerabilities. This zero-day incident reinforces a broader trend in the mobile threat landscape, where attackers increasingly target core operating system components to maximize their impact. As exploitation techniques continue to evolve, timely patching and a layered approach to security defenses remain paramount in reducing exposure and preventing device compromise.

What You Should Do

  • Update Immediately: Ensure your Android device is updated to the latest available security patch level, specifically patch level 2026-06-05 or newer.
  • Enable Google Play Protect: Verify that Google Play Protect is active on your device to scan for and warn against potentially harmful applications.
  • Avoid Sideloading Apps: Refrain from installing applications from untrusted third-party sources outside of the official Google Play Store.
  • Maintain Device Hygiene: Regularly review app permissions and uninstall any applications that are no longer needed or seem suspicious.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical WP Maps Pro Flaw Lets Attackers Create Admin Accounts

Next Post

Critical StrongDM CVE-2024-2495 Allows Auth Token Theft and Reuse

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us