Google quickly fixed 124 vulnerabilities in Android, among which one was widely exploited by attackers
Google releases June 2026 security patches for Android
ItemWhat happenedNumber of fixes124 vulnerabilities, including one zero‑day (CVE‑2025‑48595).Key vulnerabilityCVE‑2025‑48595 – an exploit that allows hackers to execute arbitrary code and elevate privileges on Android 14+; it was used in targeted attacks.Release datesJune 1 and June 5, 2026 (the second batch includes all fixes from the first).
How updates are distributed
* Google Pixel devices receive patches immediately after release.
* Third‑party device manufacturers may require additional testing to account for their hardware specifics.
History of CVE‑2025‑48595
StageDateEventMarch 2025Google discovered “limited” use of the vulnerability.June 2026The vulnerability is fully patched, but details about real attacks have not yet been disclosed.
> *Similar exploits were previously used by commercial spyware and state operations against high‑ranking individuals.*
Additional critical fixes
* 18 vulnerabilities in System, Framework, and Qualcomm closed source components – potentially allowing denial‑of‑service (DoS) attacks and privilege escalation.
* The most serious is a critical vulnerability in the Framework that allows remote privilege escalation without user interaction.
Examples of previous zero days
VulnerabilityPatch release dateDescriptionCVE‑2025‑48633 & CVE‑2025‑48572December 2025High danger level, “targeted” use.CVE‑2026‑21385 (Qualcomm Display)March 2026Zero day in Qualcomm display component.
Bug bounty program
* Google updated payouts: now up to $1.5 million for particularly dangerous Android exploits.
* Payouts for vulnerabilities discovered with AI have been reduced.
> *“Many Android vulnerabilities are difficult to exploit thanks to improvements in the latest platform versions,”* a Google spokesperson said. *“We encourage users to update Android to the latest version.”*
Conclusion
Google released an extensive set of patches covering 124 vulnerabilities, including the critical zero‑day CVE‑2025‑48595. Updates roll out quickly on Pixel and gradually on third‑party devices. The company continues active work in detecting and fixing threats while increasing rewards for serious exploits. Users are advised to upgrade to the latest Android version as soon as possible for maximum protection.
Comments (0)
Share your thoughts — please be polite and stay on topic.
Log in to comment