{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-48595",
  "revision": 1,
  "title": "Android Framework — integer overflow to local privilege escalation",
  "summary": "An integer overflow in the Android framework can be pushed into code execution, letting software already on the device gain privileges it was never granted. No extra permissions and no user interaction are needed.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.4,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01714,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-06-02",
    "prerequisites": "Code already running on the device, with no special permissions."
  },
  "remediation": {
    "patch_available": true
  },
  "kill_chain": "privilege_escalation",
  "recommended_action": "Install the June 2026 Android security patch level or later; on devices past vendor support, plan replacement — no fix will arrive for them.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-48595",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-48595",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-48595",
      "retrieved_at": "2026-09-24T06:28:59.498Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48595",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://source.android.com/docs/security/bulletin/2026/2026-06-01"
    }
  ],
  "published_at": "2026-06-01T22:16:18.093Z",
  "issued_at": "2026-09-24T06:28:59.498Z",
  "tags": [
    "android",
    "framework",
    "integer-overflow",
    "privilege-escalation",
    "mobile",
    "kev"
  ]
}
