Around 85% of phones across Africa run Android, and on 1 June 2026 Google confirmed that every recent one of them shipped with a hole attackers were already crawling through. The flaw lets someone take control of an Android phone without the owner tapping a link, opening an app, or granting a single permission. Google has now released a patch, along with fixes for 123 other security problems, but a patch only protects you once it reaches your phone, and on most South African phones that does not happen the day Google presses publish.
What Google patched, and how the flaw works
The flaw is tracked as CVE-2025-48595, and it sits in the Android Framework, the part of the operating system that decides which app is allowed to do what. Think of it as the bouncer for every program on your phone. This bug lets a piece of code talk its way past the bouncer and promote itself to a level of control it should never have, the kind of access normally reserved for the system itself. From there an attacker can reach the parts of your phone that hold your messages, your photos, your banking session, and your saved passwords.
What makes this one serious is how little the victim has to do. Most phone scams need you to slip up by tapping a dodgy link, installing a fake app, or approving a permission you should have questioned. CVE-2025-48595 needs none of that. Google has confirmed there are indications it is already being used in limited, targeted attacks, the pattern usually associated with surveillance and spyware aimed at specific people rather than a mass campaign. The company has not said who is behind it or who the targets are.
The patch arrived as part of Google's June 2026 Android Security Bulletin, published on 1 June, which fixes 124 vulnerabilities in total across Android 14, 15, 16, and the latest 16 QPR2 release. One of those 124 is the flaw under attack, and the rest are the ordinary backlog of holes that get found and closed every month, which is reason enough to install the update even if you are nobody's surveillance target.
Why this hits harder in South Africa
Android is not merely popular here, it is most of the market. It holds roughly 85% of smartphone usage across Africa according to market share data compiled in March 2026, and in South Africa Samsung alone accounts for more than half of phones in use as of mid-2025, with budget brands like Tecno, Infinix, and Itel making up close to a quarter more. Those affordable devices are how millions of South Africans bank, get paid, and run small businesses from a handset.
The problem is what happens after Google issues a fix. Google's own Pixel phones get the update first, and everyone else waits on their manufacturer, where the cheaper the phone, the longer that wait, if the update comes at all. A large number of entry-level and older Android phones in active use here will never receive the June 2026 patch, because the manufacturer stopped supporting them years ago. The phone still works, still opens your banking app, and is now carrying a publicly documented flaw with no fix on the way.
That matters because of where the money is. Digital banking fraud in South Africa rose 86% in a single year, with banking apps now the dominant channel for these attacks, according to SABRIC's Annual Crime Statistics for 2024. A flaw that hands an attacker system-level control of the phone your banking app runs on is exactly the kind of foothold that turns into a drained account.
For business owners there is a POPIA angle that is easy to miss. If a staff member's phone connects to your business email, your invoicing, or any system holding client information, that phone is part of how you process personal information. Under POPIA, the Protection of Personal Information Act, you are required to apply reasonable safeguards to that information. An unpatched phone running a known, exploitable flaw is hard to defend as a reasonable safeguard if a client ever asks how their data was protected.
What to do this week
- Check for the update and install it today. On most phones the path is Settings, then System, then System update or Software update. Look for a security patch level dated 2026-06-05, or at least 2026-06-01. If it is there, install it and restart the phone. Pixel owners will likely see it first, while Samsung, Xiaomi, Huawei, and the rest roll out on their own timelines, so check again every day or two this week rather than assuming it has not arrived.
- Find out whether your phone still gets security updates at all. In the same update screen, or on the manufacturer's website, check your model's support status. If your device stopped receiving security updates some time ago, it will not get this fix, and it should not be the phone you use for banking, work email, or anything holding personal information. Move that activity to a supported device.
- Keep Google Play Protect switched on and stop sideloading apps. Play Protect is the built-in scanner that checks apps for known threats, and installing apps from outside the Google Play Store removes that safety net entirely. This is Google's own first piece of advice alongside the patch, and it costs you nothing.
- Turn on automatic updates so you are not relying on memory. In your phone's update settings, enable automatic download and installation of security updates, and do the same for your apps in the Play Store. The next flaw like this one gets patched faster on a phone that updates itself overnight.
- If you run a business, make "phone updated" a standing check, not an afterthought. For staff devices that touch business data, ask the team to confirm they have installed the June update, and fold device updates into whatever onboarding or monthly routine you already run. Treat a staff phone the way you would treat a laptop with access to the same systems.
Where Ubuntu Guard fits
If your team uses their own phones for work and you have never looked at what those devices can reach, our cybersecurity assessment covers exactly that ground. We map which devices touch your business data, whether they are getting security updates, and where that intersects with your POPIA obligations. The report is plain language, the debrief is a normal conversation, and you walk away with a short list of what to fix and in what order. No jargon, and no pressure to buy tools you do not need.
Not sure which phones in your business are a risk? WhatsApp us and we will help you work it out: wa.me/27791595040. Or reach us at [email protected].
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za