Google has disclosed CVE-2025-48595, a critical Android zero-day vulnerability affecting the Android Framework component. The flaw enables remote privilege escalation without requiring any user interaction, making it one of the most severe categories of mobile security vulnerabilities. Unlike conventional attacks that rely on phishing links, malicious downloads, or user actions, this vulnerability can be exploited silently, allowing attackers to gain elevated privileges on targeted devices. The issue has reportedly been observed in limited, targeted attacks before the release of a public fix. Successful exploitation could allow threat actors to access sensitive information, execute malicious code with higher privileges, and maintain persistent control over compromised devices. Such access may be used to deploy spyware, monitor user activities, exfiltrate confidential data, or perform complete device takeovers. The zero-click nature of the vulnerability significantly increases its impact, particularly in targeted espionage and surveillance campaigns. Google addressed the vulnerability through the June 2026 Android security updates (security patch level 2026-06-05 or later) and informed Android partners ahead of public disclosure to facilitate patch deployment. While Android includes security measures such as sandboxing, exploit mitigations, and Google Play Protect, unpatched and unsupported devices remain vulnerable. The active exploitation of CVE-2025-48595 highlights the continued focus of threat actors on core mobile operating system components to achieve stealthy, long-term access to devices.
Researchers have uncovered a targeted cyber espionage campaign, dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned threat group SideCopy. The operation primarily targe...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-21182, a critical vulnerability affecting Oracle WebLogic Server, to its Known Exploited Vulnera...
Dashlane has revealed that it recently detected and mitigated a targeted brute-force attack aimed at a limited number of user accounts. The incident triggered the company's aut...