discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

CISA warns of active attacks exploiting Android, Linux bugs

CISA says hackers are exploiting an Android framework flaw and a Linux kernel privilege-escalation bug. Federal agencies must patch or stop using affected software by June 5.

By Bill Toulas·Jun 3·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

CISA warns of active attacks exploiting Android, Linux bugs
Image: bleepingcomputer.com

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog: a high-severity Android framework integer overflow and a Linux kernel privilege-escalation flaw. The agency says the Android issue affects Android 14 through 16, while the Linux bug can help local attackers escape containers and gain root on hosts.

Why it matters

This matters because KEV inclusion means the flaws are not just theoretical; CISA says they are being exploited or targeted in the wild. For defenders, the deadline turns this into an urgent patching and exposure-management task, especially for Android fleets and containerized Linux environments.

CISA found two dangerous bugs that bad actors may already be using: one in Android phones and one in Linux computers. One bug can help someone sneak extra control on a phone, and the other can help a person break out of a locked box and take over the computer.

Analysis

What CISA added

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog. The first is CVE-2025-48595, a high-severity integer overflow in the Android Framework that can be used to gain increased privileges. Google’s bulletin says it affects Android 14 through 16 and requires no user interaction. Google also said the flaw may be under limited targeted exploitation in the wild, but did not share technical details about the activity.

The second issue is CVE-2022-0492, a high-severity Linux kernel privilege-escalation flaw. It affects multiple kernel branches, including versions from 2.6 through 4.20 and 5.5 through 5.17. The flaw is in cgroup_release_agent_write() in the cgroups v1 subsystem. Because of insufficient authentication checks, a local attacker can bypass namespace isolation, escalate privileges, and potentially escape from a container to gain root on the host.

What defenders need to do

Google has already issued June 2026 Android patches, including the 2026-06-01 and 2026-06-05 security patch levels. For Linux, the article lists fixed versions such as 4.9.301+, 4.14.266+, 4.19.229+, 5.4.177+, 5.10.97+, 5.15.20+, 5.16.6+, and 5.17-rc3+.

Because the flaws are in KEV, U.S. federal agencies covered by BOD 22-01 must apply vendor updates and mitigations or stop using the impacted software by June 5. CISA also frames KEV as a warning system for critical infrastructure and large organizations, so the same urgency applies beyond government. Neither flaw is marked as ransomware-associated in KEV, which means CISA is signaling active exploitation without the extra ransomware flag.

Key points

  • CISA added CVE-2025-48595 and CVE-2022-0492 to its Known Exploited Vulnerabilities catalog.
  • The Android flaw affects Android 14 through 16 and can be exploited without user interaction.
  • The Linux flaw can let a local attacker escalate privileges and potentially escape a container to root on the host.
  • Federal agencies covered by BOD 22-01 must patch or stop using affected software by June 5.
  • CISA says the issues are active attack concerns, even though they are not tagged as ransomware-associated.
The Upside

The Android and Linux vendors have already identified fixes, so organizations have a clear patch path. If those updates are deployed quickly, exposure to both the mobile and container risks can drop sharply before attackers can widen their reach.

The Downside

If patches are delayed, Android devices on affected versions and Linux systems using vulnerable kernels could remain open to privilege escalation. In container-heavy environments, the Linux flaw is especially concerning because a local foothold could become host-level access.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityandroidlinuxmobileopen-sourceunited-states

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 3, 2026

Source

bleepingcomputer.com

Share

Topics

securityandroidlinuxmobileopen-sourceunited-states

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…