Android Security News

Security news specific to Android — vulnerabilities, malicious apps and patches affecting the Android ecosystem.

Android's open ecosystem and huge device fragmentation make it a persistent target for both platform-level exploits and malicious apps distributed through official and third-party stores. This feed tracks Android CVEs, malware campaigns targeting the platform, and Google's monthly security bulletins as they are reported. Fragmented patch delivery across manufacturers means many devices stay exposed long after a fix ships.

Recent Android items

CVE-2026-85094 The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access…
@cveNotify · Sep 4, 2026
CVE-2026-85085 The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with…
@cveNotify · Sep 4, 2026
CVE-2026-85050 Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chro…
@cveNotify · Sep 4, 2026
CVE-2026-85050 Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chro…
@cveNotify · Sep 3, 2026
CVE-2026-85050 Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chro…
@cveNotify · Sep 3, 2026
CVE-2026-85044 Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafte…
@cveNotify · Sep 3, 2026
StreamRat Android malware spreads through Meta and TikTok ads https://ift.tt/8Vol5Xy
@ctinow · Sep 3, 2026
CVE-2026-84117 Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. 🎖
@cveNotify · Sep 3, 2026
Gambling Goblin is hijacking traffic on compromised Brazilian government sites.Malicious Apache modules strip security headers and proxy visitors to betting pages disguised as Google Play, Microsoft S…
@thehackernews · Sep 2, 2026
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control https://ift.tt/uPEqQGs
@ctinow · Sep 2, 2026
A fake streaming ad reached an estimated 570,950 EU Meta accounts.It promoted StreamRat, an Android trojan that can gain near-complete device control after a user sideloads the APK and grants system p…
@thehackernews · Sep 2, 2026
CVE-2026-84353 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the s…
@cveNotify · Sep 2, 2026
CVE-2026-84352 Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium…
@cveNotify · Sep 2, 2026
CVE-2026-84333 Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s…
@cveNotify · Sep 2, 2026
CVE-2026-84327 Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a c…
@cveNotify · Sep 2, 2026
CVE-2026-84442 A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the compo…
@cveNotify · Sep 2, 2026
CVE-2026-84431 A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.m…
@cveNotify · Sep 2, 2026
CVE-2026-84353 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the s…
@cveNotify · Sep 2, 2026
CVE-2026-84352 Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium…
@cveNotify · Sep 2, 2026
CVE-2026-84333 Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s…
@cveNotify · Sep 2, 2026
CVE-2026-84330 UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security sever…
@cveNotify · Sep 2, 2026
CVE-2026-84135 Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155. 🎖
@cveNotify · Sep 1, 2026
This Android malware steals banking credentials even without an internet connection | Kaspersky official blog https://www.kaspersky.com/blog/manic-android-trojan/56323/
@PentestingNews · Sep 1, 2026
EncryptedSharedPreferences is Dead: Here's What You Should Use Instead - Include Security Research Blog Android application developers often store sensitive data to disk, relying on physical device se…
@malwr · Aug 31, 2026
CVE-2026-79042 Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restr…
@cveNotify · Aug 31, 2026
Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks https://gbhackers.com/android-17-adds-new-network-security-features/
@PentestingNews · Aug 31, 2026
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication https://gbhackers.com/critical-microsoft-ufo-mcp-flaw/
@PentestingNews · Aug 31, 2026
SimoneAvogadro/android-reverse-engineering-skill: Claude Code skill to support Android app's reverse engineering https://github.com/SimoneAvogadro/android-reverse-engineering-skill 🎖
@malwr · Aug 29, 2026
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers https://ift.tt/7ea1cZy
@ctinow · Aug 28, 2026
CVE-2026-79086 Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium secu…
@cveNotify · Aug 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.