Google fixes one actively exploited Android zero-day, 124 flaws
Google’s June 2026 Android patches fix 124 flaws, including an actively exploited zero-day in Android Framework.
Intelligence analysis by GPT-5.4 Mini

Google shipped June 2026 Android security updates covering 124 vulnerabilities, among them one Android Framework zero-day that was already being exploited in targeted attacks. The patch set also includes 18 critical issues and is rolling out in two levels, with Pixel devices getting it first.
Google fixed a bad door lock in Android that thieves were already trying to use. Phones that get the update are safer; phones that wait are still at risk, like leaving a window open.
Analysis
What Google fixed
Google says the June 2026 Android security update addresses 124 vulnerabilities across Android components, including one high-severity Android Framework zero-day tracked as CVE-2025-48595. The company says there are signs the flaw may be under limited, targeted exploitation, and that it can be used by a local attacker to execute code and raise privileges on Android 14 or later.
Patch levels and rollout
Google issued two patch levels, 2026-06-01 and 2026-06-05. The later bundle includes everything from the first set plus fixes for closed-source third-party and kernel subcomponents that may not apply to every device. Pixel phones are expected to receive the update immediately, while other manufacturers often take longer because they need to test and adapt the patches for specific hardware.
Broader risk
The bulletin also says Google fixed 18 critical vulnerabilities across System, Framework, and Qualcomm closed-source components. Those issues can be abused for denial-of-service or privilege escalation, and Google notes that one of the most severe could allow remote privilege escalation without any extra execution privileges and without user interaction.
Google did not provide technical detail about the active exploitation or identify targets. The article notes that similar Android flaws have previously been used by commercial spyware operators and nation-state groups against high-value people, which raises the stakes for unpatched devices.
Key points
- Google released June 2026 Android security patches for 124 vulnerabilities.
- One zero-day, CVE-2025-48595, is described as under limited targeted exploitation.
- The flaw affects Android Framework and can lead to code execution and privilege escalation on Android 14 or later.
- Google also fixed 18 critical vulnerabilities across System, Framework, and Qualcomm components.
- Pixel devices receive the updates immediately, while other vendors may take longer to ship them.
If users and vendors install the June patches quickly, the actively exploited flaw and the other critical issues should stop being easy targets on updated devices. Pixel owners get the fixes right away, which shortens exposure for that group.
Devices that lag on vendor updates stay exposed longer, especially since Google says other manufacturers often need extra time to test the patches. Because the company did not share technical details, attackers may keep probing unpatched phones while rollout is still in progress.



