IOC Radar
TLP:WHITE7 IOCs

Android 0-Day Vulnerability Exploited for Full Device Control

CP
Cyber Press
Published June 2, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYPlayINFRASTRUCTUREunknownCAPABILITYPlayVICTIMunknown
Adversary(1)
Infrastructure
Capability(1)
Victim

Attack Flow5 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/5
Exploit Public-Facing Application
ActionExploit zero-day vulnerability
Exploitation of a zero-day vulnerability (CVE-2025-48595) in the Android Framework component.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise7

TypeIndicatorConfidenceScoreFirst Seen
CVECVE-2025-48595
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2025-48572
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2026-0040
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2025-48633
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2026-0041
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2026-0042
exploitintel-blogmalware
Medium
51
Jun 2, 26
CVECVE-2026-0039
exploitintel-blogmalware
Medium
51
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph7 total IOCs
CVE
CVE7Actors1Malware1REPORTAndroid 0-Day VulnerabilitPlayPlay
scroll to zoom · drag to pan · click IOC to open