Android Security News

Security news specific to Android — vulnerabilities, malicious apps and patches affecting the Android ecosystem.

Android's open ecosystem and huge device fragmentation make it a persistent target for both platform-level exploits and malicious apps distributed through official and third-party stores. This feed tracks Android CVEs, malware campaigns targeting the platform, and Google's monthly security bulletins as they are reported. Fragmented patch delivery across manufacturers means many devices stay exposed long after a fix ships.

Recent Android items

New Android malware lets criminals use your bank card in real timehttps://ift.tt/Zxv8ebS
@ctinow · Aug 13, 2026
WindRelay turns Android phones into live contactless payment proxies.Attackers use SpyNote access to silently install the NFC relay malware. When victims tap a physical card on the infected phone, Win…
@thehackernews · Aug 13, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-0299Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on mac…
@cveNotify · Aug 13, 2026
CVE-2026-0298An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a…
@cveNotify · Aug 13, 2026
CVE-2026-0296Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify ap…
@cveNotify · Aug 13, 2026
CVE-2026-0295A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.The GlobalProtect ap…
@cveNotify · Aug 13, 2026
CVE-2026-0294A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. Th…
@cveNotify · Aug 13, 2026
CVE-2026-0293A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized ac…
@cveNotify · Aug 13, 2026
CVE-2026-0292An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequentl…
@cveNotify · Aug 13, 2026
CVE-2026-0291An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete sy…
@cveNotify · Aug 13, 2026
Android malware combo takes out loans and relays victims' credit cardshttps://ift.tt/rnVmF4h
@ctinow · Aug 12, 2026
CVE-2026-45799Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-run…
@cveNotify · Aug 12, 2026
CVE-2026-73296Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/c…
@cveNotify · Aug 12, 2026
CVE-2026-67568The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or…
@cveNotify · Aug 12, 2026
WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraudhttps://gbhackers.com/windrelay-turns-android-phones/
@PentestingNews · Aug 12, 2026
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abusehttps://ift.tt/5Vlpesq
@ctinow · Aug 12, 2026
CVE-2026-67568The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or…
@cveNotify · Aug 11, 2026
CVE-2026-67558The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic periph…
@cveNotify · Aug 11, 2026
CVE-2026-66832When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent use…
@cveNotify · Aug 11, 2026
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsinghttps://ift.tt/OMq6mPJ
@ctinow · Aug 11, 2026
Kimwolf v7 makes DDoS traffic harder to distinguish from real browsing.The Android and IoT botnet now builds complete browser fingerprints for HTTP/2 floods, uses ENS and Tor to harden its C2, and tar…
@thehackernews · Aug 11, 2026
CVE-2026-65768Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.🎖@cveNotify
@cveNotify · Aug 11, 2026
CVE-2026-65767Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.🎖@cve…
@cveNotify · Aug 11, 2026
Navi Mumbai Cyber Fraud Surge: APK Scams Cause ₹2.68 Crore Loss In 42 Cases Till Julyhttps://ift.tt/HhV4XPb
@ctinow · Aug 11, 2026
Navi Mumbai Cyber Fraud: Kharghar Resident Loses ₹8.39 Lakh After Fraudsters Posing As Mahanagar Gas Staff Send APK File; Case Registeredhttps://ift.tt/zaPd6xO
@ctinow · Aug 11, 2026
CVE-2026-34490Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Se…
@cveNotify · Aug 10, 2026
CVE-2026-59112Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiD…
@cveNotify · Aug 10, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.