Google issued Android security updates to fix multiple high-severity flaws, including CVE-2026-0049, a critical Android Framework vulnerability that can trigger a local denial-of-service with no user interaction and no elevated privileges, and CVE-2026-0073, a critical remote code execution bug in the Android System component tied to the Android Debug Bridge Daemon (adbd). The adbd flaw affects Android 14, 15, 16, and 16-qpr2, and under proximal or adjacent network conditions could allow shell-level remote code execution on a target device without user action.
The April bulletin also addressed CVE-2025-48651, a high-severity StrongBox issue affecting hardware-backed key storage implementations from Google, NXP, STMicroelectronics, and Thales, with fixes split between the 2026-04-01 and 2026-04-05 patch levels. Google said the adbd issue is remediated by the 2026-05-01 security patch level or later and noted that, because adbd is delivered through Project Mainline, mitigations can reach Android 10 and later devices faster through Google Play system updates; organizations were urged to accelerate deployment of the April and May patches across managed mobile fleets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Google said devices should be updated to the 2026-05-01 security patch level or later to remediate CVE-2026-0073, noting that because adbd is delivered through Project Mainline, fixes can also be distributed quickly through Google Play system updates on Android 10 and later. Organizations were urged to prioritize immediate deployment across mobile fleets.
Google's May 2026 Android Security Bulletin addressed CVE-2026-0073, a critical zero-click remote code execution flaw in the Android System component tied to adbd under Project Mainline. The vulnerability affected Android 14, 15, 16, and 16-qpr2 and could allow shell-level remote code execution in proximal or adjacent network conditions without user interaction.
Alongside the April bulletin, Google said Android Open Source Project source code patches would be released within 48 hours of publication and urged users to install the April 2026 updates promptly. This was part of the coordinated rollout of the April fixes.
Google released the April 2026 Android Security Bulletin addressing multiple flaws, including CVE-2026-0049, a critical zero-interaction vulnerability in the Android Framework that could cause a local denial-of-service without user action or elevated privileges. The bulletin split fixes across the 2026-04-01 and 2026-04-05 patch levels and included remediation for the high-severity StrongBox issue CVE-2025-48651.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.