Android fixes 124 security vulnerabilities and one exploited critical flaw

Last update: 29 June, 2026
  • The June update fixes a total of 124 security bugs in the Android ecosystem.
  • The CVE-2025-48595 vulnerability has been identified as a critical threat that is already being exploited by attackers.
  • The patch is distributed in two phases, covering both the core system and components from manufacturers such as Qualcomm and MediaTek.
  • System fragmentation means that Pixel and Samsung devices receive protection much sooner than mid-range or budget devices.

Android security

A package of security patches for Android has just been released, notable for its size and urgency. This June update is no ordinary release, as the Google team has had to work tirelessly to patch a total of 124 holes in the operating systemAmong them all, one is particularly worrying because it is already being exploited by real attackers on devices that do not have adequate protection.

The news broke after unusual activity was detected exploiting a critical security flaw. Unlike other patches that prevent theoretical risks, this time we are facing a confirmed threat. It affects the latest versions. of Android. Therefore, if you have a mobile phone handy, it's best to check the settings to see if you can already install this new version and thus avoid unnecessary surprises.

Android security patch June 2026
Related articles:
The June Android security patch protects your device against targeted attacks

A critical failure that does not require user interaction.

Vulnerabilities in the system

It is vital to understand that the most dangerous vulnerability, called CVE-2025-48595 is located in the Android FrameworkThis means the vulnerability lies in one of the deepest parts of the software, allowing a potential attacker to escalate their privileges without the device owner having to take any action, such as clicking on suspicious links or downloading malware. malicious Android apps.

Google has confirmed that there are indications of targeted attacks exploiting this vulnerability, although for now it appears to be limited in scope. Because it is located in the system's core, the risk extends equally to devices with Android 14, 15 and 16This situation requires extreme caution, since the backdoor is open in a layer shared by almost all modern smartphones, regardless of brand.

Android security to avoid hackers and fake apps
Related articles:
Android device security: how to protect your phone against intruders and malicious apps

Patch structure and deployment phases

Software update

To better organize the cleanup of these bugs, the company has divided the update into two phases. The first, dated June 1st, focuses on the main components of the Android frameworkwhere 18 critical vulnerabilities have been resolved. This is the first line of defense to prevent the core software from being vulnerable to external intrusions.

On the other hand, there is a second phase, dated June 5th, that goes a step further. This second package includes Kernel and driver improvements specific to major hardware manufacturers like MediaTek or Qualcomm. For a user to be considered fully protected, their phone should display one of these two dates in the system security settings.

The problem of fragmentation in current mobile phones

Device protection

Although Google has already done its part by releasing the code, the time it takes for the update to reach you depends entirely on who manufactured your phone. The models Google Pixel phones are usually the first in receiving the notification, followed very closely by Samsung's high-end terminals that integrate Advanced security with Samsung KnoxHowever, for those who use mid-range phones or devices that have been on the market for a couple of years, the wait can feel endless.

This difference in update times is what we call fragmentation, and it's the reason why millions of people remain vulnerable weeks after a fix is ​​available. It's a shame, but an affordable device that It still has a useful life ahead of it It could take months to receive this much-needed patch, leaving a window of opportunity for cybercriminals.

To check if you're safe, simply go to your phone's settings, find the security and privacy section, and check the system update status. If you see a date earlier than June, it's best to... Click the check for updates button Manually force the download. It takes no time at all, and considering that there are people out there trying to exploit these vulnerabilities, it's one of the best ways to use it. Essential apps to improve security on Android and rest assured about the privacy of your data.

Alternative Operating Systems on Android
Related articles:
Android options you should disable (and which ones to keep) to improve your security