Android flaws exploited in the wild
Android, Samsung, Qualcomm, Arm and MediaTek flaws used in attacks, with Android security news.
Log in – next time you'll see what's new since your visit.
Timeline
Anubis Malware in 2026: Android Trojan and Ransomware
Anubis malware is two threats in 2026: the leaked Android banking trojan with a ransomware lock and a separate Windows ransomware group with a wiper mode.
Article →Is Fortnite Safe on Android in 2026? Malware and Fakes
Fortnite is not a virus, and in 2026 it is back on Google Play. The 2018 Android installer flaw, fake Fortnite APKs that spread malware, and safe steps.
Article →CVE-2026-58704 added to CISA's exploited list: Google Pixel Improper Authorization Vulnerability
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
2-Spyware: exploited vulnerability →CVE-2025-48595 added to CISA's exploited list: Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
2-Spyware: exploited vulnerability →CVE-2026-21385 added to CISA's exploited list: Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
2-Spyware: exploited vulnerability →CVE-2025-48572 added to CISA's exploited list: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
2-Spyware: exploited vulnerability →CVE-2025-48633 added to CISA's exploited list: Android Framework Information Disclosure Vulnerability
Android Framework contains an unspecified vulnerability that allows for information disclosure.
2-Spyware: exploited vulnerability →CVE-2025-21042 added to CISA's exploited list: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
2-Spyware: exploited vulnerability →CVE-2025-21043 added to CISA's exploited list: Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
2-Spyware: exploited vulnerability →CVE-2025-48543 added to CISA's exploited list: Android Runtime Use-After-Free Vulnerability
Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
2-Spyware: exploited vulnerability →CVE-2025-27038 added to CISA's exploited list: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
2-Spyware: exploited vulnerability →CVE-2025-21480 added to CISA's exploited list: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
2-Spyware: exploited vulnerability →CVE-2025-21479 added to CISA's exploited list: Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
2-Spyware: exploited vulnerability →CVE-2024-43093 added to CISA's exploited list: Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
2-Spyware: exploited vulnerability →CVE-2024-43047 added to CISA's exploited list: Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
2-Spyware: exploited vulnerability →CVE-2024-36971 added to CISA's exploited list: Android Kernel Remote Code Execution Vulnerability
Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.
2-Spyware: exploited vulnerability →CVE-2024-32896 added to CISA's exploited list: Android Pixel Privilege Escalation Vulnerability
Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
2-Spyware: exploited vulnerability →CVE-2024-4610 added to CISA's exploited list: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
2-Spyware: exploited vulnerability →