Android Security News

Security news specific to Android: vulnerabilities, malicious apps and patches affecting the Android ecosystem.

Android's open ecosystem and device fragmentation make it a persistent target, both for platform-level exploits and for malicious apps distributed through official and third-party stores. Android CVEs, malware campaigns targeting the platform, and Google's monthly security bulletins land here. Patch delivery across manufacturers is fragmented, so many devices stay exposed long after a fix ships.

Recent Android items

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims 🖋️ RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according…
@cibsecurity · Sep 28, 2026
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims https://ift.tt/PbhWLZu
@ctinow · Sep 28, 2026
RatHat, an Android banking trojan, uses Gemini to rank infected phones by estimated bank balance. Cleafy traced nearly 100 console deployments since April 2026. Gemini helps operators prioritize victi…
@thehackernews · Sep 28, 2026
Unprivileged_Android_app_can_abort_the_Identity_Credential_HAL https://github.com/infectedcoffee/MISC/blob/main/AF-03-FORM.md
@secharvester · Sep 27, 2026
CVE-2026-101042 Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagra…
@cveNotify · Sep 27, 2026
newliver666/apk-reverse: Suitable for Android APK reverse engineering analysis https://github.com/newliver666/apk-reverse An Agent Skill for Android APK reverse engineering, debloating, ad removal, su…
@malwr · Sep 27, 2026
CVE-2026-0014 In isPackageNullOrSystem of AppOpsService.java , there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no add…
@cveNotify · Sep 27, 2026
CVE-2025-58483 Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store. 🎖
@cveNotify · Sep 26, 2026
CVE-2025-21080 Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege. 🎖
@cveNotify · Sep 26, 2026
CVE-2025-48593 In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional executi…
@cveNotify · Sep 26, 2026
CVE-2026-100379 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue…
@cveNotify · Sep 25, 2026
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities https://ift.tt/UpBm9q7
@ctinow · Sep 25, 2026
Windows, Linux, Android File Notification Systems Leak User Activity https://ift.tt/wQdRYfO
@ctinow · Sep 25, 2026
CVE-2026-0014 In isPackageNullOrSystem of AppOpsService.java , there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no add…
@cveNotify · Sep 25, 2026
CVE-2026-84283 Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to…
@cveNotify · Sep 25, 2026
Decades-old file security flaws found in Android, Linux, macOS, and Windows https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/529…
@secharvester · Sep 24, 2026
Wedding invite APK opens door to ₹2.62 lakh cyber fraud https://ift.tt/UkGF0LK
@ctinow · Sep 24, 2026
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions https://ift.tt/okBZnVW
@ctinow · Sep 24, 2026
CVE-2026-58941 In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional exec…
@cveNotify · Sep 24, 2026
CVE-2026-58848 In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional executi…
@cveNotify · Sep 24, 2026
CVE-2026-58846 In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privi…
@cveNotify · Sep 24, 2026
CVE-2026-58839 In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privi…
@cveNotify · Sep 24, 2026
CVE-2026-58823 In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional…
@cveNotify · Sep 24, 2026
CVE-2026-58822 In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges ne…
@cveNotify · Sep 24, 2026
CVE-2026-58820 In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required…
@cveNotify · Sep 24, 2026
CVE-2026-55256 In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional…
@cveNotify · Sep 24, 2026
CVE-2026-49932 In parseParts of PduParser.java , there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution pri…
@cveNotify · Sep 24, 2026
CVE-2026-49927 In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges neede…
@cveNotify · Sep 24, 2026
CVE-2026-49919 In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execut…
@cveNotify · Sep 24, 2026
CVE-2026-49918 In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges neede…
@cveNotify · Sep 24, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.