Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google fixed 124 Android flaws in June 2026, including one high-severity Framework bug that is already seeing limited targeted exploitation.
Intelligence analysis by GPT-5.4 Mini

Google’s June Android update is notable less for the raw patch count than for one flaw already under active exploitation. The company says the issue enables local privilege escalation without user interaction, and the broader release also covers System, kernel, and chipset components.
Google found lots of holes in Android and fixed them. One hole was already being used by attackers, kind of like a lock on a door that thieves have figured out how to pick, so phones need the update fast.
Analysis
Google’s June 2026 Android bulletin covers 124 security vulnerabilities across the platform. The headline issue is CVE-2025-48595, a high-severity flaw in the Framework component with a CVSS score of 8.4. According to the article, Google says there are signs the bug may be under “limited, targeted exploitation.” The flaw affects devices running Android 14, 15, 16, and 16 QPR2, and the vulnerability description says it can lead to local escalation of privilege without requiring user interaction.
The article ties this kind of weakness to the sort of flaw that can matter in highly targeted attacks. It notes that similar bugs have been used by commercial spyware vendors against high-profile individuals, which is why an exploited privilege-escalation issue in Android gets immediate attention from defenders.
Google also patched a range of other issues in the System component, including at least one severe bug that could also lead to local escalation of privilege without extra privileges. The company published two patch levels for the month: 2026-06-01 and 2026-06-05. The later level includes everything in the earlier one, plus fixes for kernel and third-party chipset components from Imagination Technologies, MediaTek, Qualcomm, and Unisoc.
For defenders, the key takeaway is straightforward: the June Android update is not just routine maintenance. It includes a flaw with signs of active exploitation, so patching quickly matters more than usual.
Key points
- Google released June 2026 Android patches for 124 vulnerabilities.
- CVE-2025-48595 is a high-severity Framework flaw with signs of limited, targeted exploitation.
- The bug affects Android 14, 15, 16, and 16 QPR2 and can enable local privilege escalation without user interaction.
- Google published 2026-06-01 and 2026-06-05 patch levels, with the latter including kernel and chipset fixes.
- The update also covers System-component vulnerabilities and third-party fixes from several chip vendors.
If device makers and users apply the June 2026 patches quickly, the actively exploited flaw and the other serious bugs should stop being useful on updated devices. The two patch levels also give vendors a clear path to ship the core fixes first and the broader chipset and kernel fixes after.
If updates are delayed, devices on older patch levels may stay exposed to targeted attacks that do not require user interaction. The article also suggests that the exploitation is limited and targeted, which means the risk may persist for high-value users until patch adoption catches up.



