CVE-2025-48595 is a high-severity integer overflow vulnerability in multiple locations within the Android Framework. The flaw affects Android 14, Android 15, Android 16, and Android 16 QPR2. An attacker with local code execution can exploit the overflow to achieve code execution and elevate privileges. Google reported indications of limited, targeted exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small Android proof-of-concept app for CVE-2025-48595. It is not part of a common exploit framework. The repository contains a standard Gradle Android project with one primary Java source file, AndroidManifest metadata, minimal resources, and a GitHub Actions workflow that builds a debug APK. The core exploit logic is entirely in app/src/main/java/com/cve202548595/MainActivity.java. When launched, the app starts a background thread that enumerates several Binder-exposed Android system services: activity, package, window, notification, power, and alarm. For each service, it uses reflection to call android.os.ServiceManager.getService(), obtains an IBinder handle, performs repeated one-way transactions that appear intended to shape heap/layout state, and then sends crafted Parcel payloads containing suspicious integer values (0x40000001, 0x80000001, 0x20000003) across transaction codes 1 through 20. The exploit treats a DeadObjectException as evidence that system_server crashed, which is its primary success condition. Capabilities are limited to local exploitation from an installed Android app. There is no remote C2, no network beaconing, no persistence, and no post-exploitation payload beyond attempting denial-of-service against privileged Android services/system_server. The app also reads /proc/self/attr/current to log its SELinux context, likely to help the operator understand the execution environment. Repository structure is straightforward: build.gradle and app/build.gradle define the Android build; AndroidManifest.xml declares a debuggable launcher activity; strings.xml contains only the app name; .github/workflows/build.yml automates APK compilation and artifact upload. Overall, this is a focused Binder IPC crash PoC intended to validate or demonstrate a local Android vulnerability rather than provide a full exploitation chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
138 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity vulnerability in Android's Framework component that Google stated had been actively exploited before patches were issued in June 2026.
An Android Framework zero-day that could allow code execution and privilege escalation on devices running Android 14 or later.
An actively exploited Android Framework zero-day allowing code execution and privilege escalation on Android 14 and later.
A high-severity Android Framework privilege escalation vulnerability caused by integer overflow in multiple locations, allowing a malicious app to achieve local code execution and privilege escalation without user interaction or additional permissions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.