F-Droid 2.0 Modernizes Android App Discovery but Leaves Some Privacy Tools Behind
F-Droid 2.0 brings the open-source Android repository its largest client redesign in a decade, with improved search, automatic updates and a modernized codebase. Privacy-conscious users should note that...
Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures
Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...
New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos
A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...
Eight-Year-Old Samsung KNOX Flaw Exposed Hundreds of Millions of Galaxy Devices to Kernel Attacks
A critical use-after-free vulnerability in Samsung's KNOX PROCA subsystem — undetected for 8 years — could allow kernel-level compromise on Galaxy S9 through S25 devices. Patch is available...
CVE-2025-48595: Android 0-Day Actively Exploited — Patch Your Devices Now
Google has confirmed active exploitation of CVE-2025-48595, a zero-click Android Framework privilege escalation flaw affecting Android 14-16. Devices without the June 2026 patch remain at risk of complete...
Android 16 ‘Tiny UDP Cannon’ Flaw Lets Malicious Apps Bypass VPN and Expose Your Real IP Address
A newly disclosed Android 16 design flaw dubbed 'Tiny UDP Cannon' allows any app with basic permissions to bypass VPN lockdown mode and reveal the device's real IP...
Google Project Zero Reveals Silent Zero-Click Exploit Chain Rooting Pixel 10 Devices
Google Project Zero has demonstrated a two-vulnerability chain that silently roots Google Pixel 10 devices without any user interaction, combining a Dolby media framework flaw with a newly...
PoC Exploit Released for Android Zero-Click CVE-2026-0073 — Silent ADB Shell Access on Android 14–16
A public PoC exploit for CVE-2026-0073 enables any network-local attacker to gain a full ADB shell on unpatched Android 14–16 devices with zero user interaction, exploiting a cryptographic...