CyberMax
Home › Exploited CVEs › Android

Android Framework known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 6 Android Framework CVEs as exploited in the wild. 3 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 6 Android Framework CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2023-35674Framework Privilege Escalation2.6%–2023-09-132023-10-04
2CVE-2025-48595Framework Integer Overflow1.7%–2026-06-022026-06-05
3CVE-2023-20963Framework Privilege Escalation1.5%–2023-04-132023-05-04
4CVE-2024-43093Framework Privilege Escalation0.7%–2024-11-072024-11-28
5CVE-2025-48633Framework Information Disclosure0.3%–2025-12-022025-12-23
6CVE-2025-48572Framework Privilege Escalation0.3%–2025-12-022025-12-23
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Android KEV CVEs · free KEV badge for Android · all vendors