{"id":475913,"date":"2026-05-09T05:43:36","date_gmt":"2026-05-09T05:43:36","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/475913\/"},"modified":"2026-05-09T05:43:36","modified_gmt":"2026-05-09T05:43:36","slug":"update-android-now-google-confirms-critical-zero-click-vulnerability","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/475913\/","title":{"rendered":"Update Android Now\u2014Google Confirms Critical Zero-Click Vulnerability"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.europesays.com\/ie\/wp-content\/uploads\/2026\/05\/1778305416_412_0x0.jpg\" alt=\"Android logo is seen displayed on a smartphone screen.\" data-height=\"2187\" data-width=\"3282\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Update Android now\u2014zero-click vulnerability confirmed by Google.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>The newly published May 2026 Android security bulletin comes with one clear warning: update now if you use Android 14, Android 15, Android 16, and Android 16-QPR2. The reasoning is simple enough, as a critical Google Android System component vulnerability can give an attacker remote shell access without any user interaction required. That\u2019s right, this is a zero-click vulnerability, and that\u2019s why it is so dangerous. What the attacker does need, however, is to be on the same local network, more physically close to the target device, which does at least mitigate the risk.  That said, the advice to update now stands; why take any chances when the solution is simple enough and doing nothing effectively gives an attacker a master key that evades security detection.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1 link-embed--long-title\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/05\/microsoft-says-edge-password-security-vulnerability-is-by-design-is-it-time-to-switch-to-chrome\/\" target=\"_blank\" aria-label=\"Microsoft Says Edge Password Security Vulnerability Is \u2018By Design\u2019\u2014Is It Time To Switch To Chrome?\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/05\/microsoft-says-edge-password-security-vulnerability-is-by-design-is-it-time-to-switch-to-chrome\/\" rel=\"nofollow noopener\">ForbesMicrosoft Says Edge Password Security Vulnerability Is \u2018By Design\u2019\u2014Is It Time To Switch To Chrome?By Davey Winder<\/a>The Critical CVE-2026-0073 Google Android Zero-Click Vulnerability Explained<\/p>\n<p>Tracked by the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_self\" aria-label=\"Common Vulnerabilities and Exposures\" rel=\"nofollow noopener\">Common Vulnerabilities and Exposures<\/a> system as CVE-2026-0073, Google has confirmed that this core Android System component vulnerability could \u201clead to remote (proximal\/adjacent) code execution as the shell user with no additional execution privileges needed,\u201d adding that \u201cuser interaction is not needed for exploitation.\u201d<\/p>\n<p>While there is no evidence to suggest that the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/03\/11\/critical-0-click-microsoft-excel-security-bug-lets-copilot-steal-data\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/03\/11\/critical-0-click-microsoft-excel-security-bug-lets-copilot-steal-data\/\" target=\"_self\" aria-label=\"zero-click\" rel=\"nofollow noopener\">zero-click<\/a> vulnerability has been exploited in the wild at this stage, it would not be unusual for this to happen as more technical details emerge. Currently, according to <a class=\"color-link\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0073\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0073\" aria-label=\"CVE.org\">CVE.org<\/a> it is known that \u201cIn adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code.\u201d The wireless Android Debug Bridge is meant to be a secure method for developer interaction with devices, but CVE-2026-0073 appears to have exploited the way that the encryption works with ADB to effectively give an attacker a master key to access a device by way of impersonation of a trusted source. What it does is enable remote code execution by way of a shell that can bypass application sandboxes. And that, dear reader, is a bad thing. <\/p>\n<p>\u201cSecurity patch levels of 2026-05-01 or later address all of these issues,\u201d Google said, while confirming: \u201cThe issue in this bulletin is a critical security vulnerability.\u201d That rating having been applied, Google said, due to the \u201ceffect that exploiting the vulnerability would possibly have on an affected device.\u201d<\/p>\n<p>While the fractured nature of the Android ecosystem means that your device might not yet have an update available, Google has already notified all hardware vendors of the vulnerability well in advance of the <a class=\"color-link\" href=\"https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-05-01\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/source.android.com\/docs\/security\/bulletin\/2026\/2026-05-01\" aria-label=\"May Android security bulletin\">May Android security bulletin<\/a> publication on May 4, so hopefully your update will be here already.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/02\/meta-discloses-2-whatsapp-vulnerabilities-in-new-security-advisory\/\" target=\"_blank\" aria-label=\"Meta Discloses 2 WhatsApp Vulnerabilities In New Security Advisory\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/05\/02\/meta-discloses-2-whatsapp-vulnerabilities-in-new-security-advisory\/\" rel=\"nofollow noopener\">ForbesMeta Discloses 2 WhatsApp Vulnerabilities In New Security AdvisoryBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Update Android now\u2014zero-click vulnerability confirmed by Google. SOPA Images\/LightRocket via Getty Images The newly published May 2026 Android&hellip;\n","protected":false},"author":2,"featured_media":475914,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257],"tags":[5226,67752,208472,208475,18,823,20095,208474,19,17,279,82,208473],"class_list":{"0":"post-475913","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-android-security","9":"tag-android-security-update","10":"tag-android-zero-click-security-vulnerability","11":"tag-cve-2026-0073","12":"tag-eire","13":"tag-google","14":"tag-google-android","15":"tag-google-security-update","16":"tag-ie","17":"tag-ireland","18":"tag-mobile","19":"tag-technology","20":"tag-update-android-now"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ie\/116543030271716429","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/475913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=475913"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/475913\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/475914"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=475913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=475913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=475913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}