惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
D
Docker
腾讯CDC
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
IT之家
IT之家
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
Vercel News
Vercel News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
博客园 - 【当耐特】

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
Update Android Now—Google Confirms Critical Zero-Click Vu...
Davey Winder · 2026-05-05 · via Forbes - Consumer Tech
Android logo is seen displayed on a smartphone screen.

Update Android now—zero-click vulnerability confirmed by Google.

SOPA Images/LightRocket via Getty Images

The newly published May 2026 Android security bulletin comes with one clear warning: update now if you use Android 14, Android 15, Android 16, and Android 16-QPR2. The reasoning is simple enough, as a critical Google Android System component vulnerability can give an attacker remote shell access without any user interaction required. That’s right, this is a zero-click vulnerability, and that’s why it is so dangerous. What the attacker does need, however, is to be on the same local network, more physically close to the target device, which does at least mitigate the risk. That said, the advice to update now stands; why take any chances when the solution is simple enough and doing nothing effectively gives an attacker a master key that evades security detection.

ForbesMicrosoft Says Edge Password Security Vulnerability Is ‘By Design’—Is It Time To Switch To Chrome?

The Critical CVE-2026-0073 Google Android Zero-Click Vulnerability Explained

Tracked by the Common Vulnerabilities and Exposures system as CVE-2026-0073, Google has confirmed that this core Android System component vulnerability could “lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed,” adding that “user interaction is not needed for exploitation.”

While there is no evidence to suggest that the zero-click vulnerability has been exploited in the wild at this stage, it would not be unusual for this to happen as more technical details emerge. Currently, according to CVE.org it is known that “In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code.” The wireless Android Debug Bridge is meant to be a secure method for developer interaction with devices, but CVE-2026-0073 appears to have exploited the way that the encryption works with ADB to effectively give an attacker a master key to access a device by way of impersonation of a trusted source. What it does is enable remote code execution by way of a shell that can bypass application sandboxes. And that, dear reader, is a bad thing.

“Security patch levels of 2026-05-01 or later address all of these issues,” Google said, while confirming: “The issue in this bulletin is a critical security vulnerability.” That rating having been applied, Google said, due to the “effect that exploiting the vulnerability would possibly have on an affected device.”

While the fractured nature of the Android ecosystem means that your device might not yet have an update available, Google has already notified all hardware vendors of the vulnerability well in advance of the May Android security bulletin publication on May 4, so hopefully your update will be here already.

ForbesMeta Discloses 2 WhatsApp Vulnerabilities In New Security AdvisoryBy Davey Winder