Topic: android security
-
Google Patches Actively Exploited Zero-Day Vulnerabilities
Google has released a critical Android security update patching over 100 vulnerabilities, including three severe flaws that are under active, targeted exploitation. Two high-severity information disclosure vulnerabilities (CVE-2025-48633 & CVE-2025-48572) can expose sensitive data or grant elevat...
Read More » -
Android's December 2025 Security Patch: A Major Update
Google's December 2025 Android Security Bulletin details numerous critical vulnerabilities, including a severe flaw in the Android Framework that could enable remote denial-of-service attacks without special privileges. The update addresses high-severity system and kernel-level vulnerabilities th...
Read More » -
Google Mandates Identity Verification for All Android Developers
Google will require all Android developers to verify their identity, regardless of where they distribute apps, to enhance security and reduce fraud. This policy aims to combat malware, as sideloaded apps are 50 times more likely to contain malicious software compared to those from the Pla...
Read More » -
Beware the 'Pixnapping' Android Attack: What It Is & Why It Matters
Pixnapping is a new Android attack method that uses transparent screen layers to stealthily capture and reconstruct on-screen pixel data, including sensitive two-factor authentication codes. Google has released a partial patch to restrict the blur function enabling this exploit, but researchers f...
Read More » -
Android Power Users Can Bypass Sideloading Limits
Google is implementing a new developer verification system requiring identity registration for apps distributed outside the Play Store to combat malware and scams. The policy has faced backlash for centralizing control and complicating app distribution, leading Google to offer concessions like a ...
Read More » -
Android Outshines iPhone in Scam Protection
Android devices, particularly Google Pixels, demonstrate superior scam protection with users significantly less likely to receive scam texts compared to iPhone users, based on Google and independent research. Independent analyses reveal Android employs AI across nine security layers for proactive...
Read More » -
Beware: Spyware Poses as Signal and ToTok Messaging Apps
Cybersecurity experts discovered two spyware operations, ProSpy and ToSpy, which impersonate updates for Signal and ToTok to target Android users, particularly in the UAE, through fake websites. These malicious apps steal sensitive data like contacts, messages, and files by tricking users into gr...
Read More » -
Google Reverses New Android Developer Registration Rules
Google has reversed its planned identity verification mandate for Android developers after significant community criticism, introducing specialized account types for limited app distribution and a method for advanced users to sideload unverified apps. The original policy, requiring government ID ...
Read More » -
Android Blocks 58% More Spam Texts Than iPhone, Google Finds
Android smartphones, particularly Google Pixel models, significantly outperform iPhones in blocking spam and scam text messages, with users experiencing far fewer unwanted messages. Google attributes this advantage to its protective measures, including RCS safety verification, anti-phishing syste...
Read More » -
Google Shuts Down Major Residential Proxy Networks
Google dismantled the IPIDEA residential proxy network, a major tool for cybercriminals to hide malicious traffic by routing it through compromised home and business devices. The operation combined legal action, intelligence sharing, and platform security, with Google Play Protect now blocking ma...
Read More » -
Secure Your WhatsApp Backups with Passkeys
WhatsApp is introducing a password-free method to encrypt chat backups using device authentication like facial recognition, fingerprint, or screen lock PIN. This update eliminates the previous need for a 64-digit key or separate password, simplifying the process and enhancing security for stored ...
Read More » -
Google Shuts Down IPIDEA Proxy Networks Powered by Malware
Google and partners dismantled the IPIDEA residential proxy network, which was secretly routing malicious traffic through millions of compromised devices via trojanized apps. The network was used by over 550 threat groups for activities like account takeovers and DDoS attacks, masking their origi...
Read More »