Back in June 2026, Google shipped patches for a high-severity flaw in Android’s Framework component (CVE-2025–48595, CVSS score: 8.4) that it said came under active exploitation.
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026, added CVE-2026–58704 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 19, 2026.
