Critical Android vulnerability CVE-2026
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-0073 | In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-21385 | Memory Corruption in Qualcomm Snapdragon Chipset Firmware Exploited in the Wild CVE-2026-21385 is a memory corruption flaw (CWE-190, integer overflow) in how firmware on a range of Qualcomm Snapdragon chipsets and Qualcomm smart-audio/display platforms handles alignment during memory allocation. It is triggered locally by low-privileged code that performs aligned memory allocations, allowing an attacker running on the device (for example, a malicious app or component) to corrupt memory. Successful exploitation yields high confidentiality, integrity, and availability impact — effectively kernel-level compromise or privilege escalation on the affected device. Affected devices include Android phones built on the listed Snapdragon SoCs (e.g., Snapdragon 429, 4 Gen 1/2, and several 8-series variants) plus Smart Audio 400 and Smart Display 200 platform firmware; Google confirmed it is being exploited in an Android component and shipped a fix in its March 2026 Android security bulletin. The flaw is actively exploited (added to CISA's KEV on 2026-03-03), though no public proof-of-concept is known and ransomware use is unknown. Do: Patch Android devices to the March 2026 Android security bulletin level (patch level 2026-03-01 or later) or the OEM's equivalent Qualcomm firmware update, prioritizing devices on the listed Snapdragon SoCs; check the installed patch level under Settings > Security > Android security update. Federal/managed environments should follow BOD 22-01 guidance per the CISA KEV entry, and owners of Smart Audio 400 / Smart Display 200-based products should obtain updated firmware from their OEM. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (listed Snapdragon SoCs span flagship 8-series through entry-level 4-series Android phones) |
Full article223 words · extracted from securityaffairs.com · click to collapse

Google patched a critical Android flaw (CVE‑2026‑0073) that lets attackers run code remotely without user action.
Google released a security update for Android to address a critical remote code execution flaw, tracked as CVE‑2026‑0073, in the System component. The bug allowed attackers to run code as the shell user without needing extra permissions, or any user interaction.
The patch prevents potential full device compromise from remote exploitation.
“The vulnerability in this section could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.” reads the advisory.
The flaw impacts ‘adbd’ (Android Debug Bridge daemon), the background process on an Android device that enables communication with a computer through the Android Debug Bridge (ADB) tool.
Google is not aware of any public exploits for this issue or of attacks in the wild exploiting CVE-2026-0073.
In March, Google confirmed that another vulnerability, tracked as CVE-2026-21385 (CVSS score of 7.8), in open-source Qualcomm component has been actively exploited.
The flaw is a buffer over-read in the Graphics component that could allow attackers to access sensitive memory data, underscoring ongoing risks to Android users.
The company did not disclose technical details about the attacks exploiting this vulnerability.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Google)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/191710/breaking-news/critical-android-vulnerability-cve-2026-0073-fixed-by-google.html