Sanctioned Russian firm identifies multiple security vulnerabilities in Android and Apple devices

When you buy through links on our articles, Future and its syndication partners may earn a commission.

Credit: Shutterstock
  • A macOS flaw could give hostile apps the highest system privileges
  • An NFC tag could trigger an Android app without owner approval
  • Android flaw lets apps change Wi-Fi settings without requesting extra permissions

In a recent revelation, Russian cybersecurity firm Positive Technologies has identified 11 security vulnerabilities that impact both Android and Apple devices. These findings were shared with the Russian news agency TASS. Notably, nine of these vulnerabilities pertain to Apple’s ecosystem, while two are specific to Android, including Pixel devices, and have been classified as high severity.

How a tag and an app exposed Android phones

The first Android vulnerability allows attackers to exploit a crafted NFC tag, enabling them to fetch, set up, and execute an app without any approval from the device owner. The second vulnerability permits an already installed app to modify network settings—such as connecting to a specific Wi-Fi network—without requiring additional permissions. This includes the ability to add certificates or adjust proxy parameters, all without the owner’s consent.

Google has addressed both Android vulnerabilities in its September 2026 security patches. Devices that have installed these updates should no longer be susceptible to these issues. The NFC tag flaw is particularly concerning, as simply bringing a phone near the tag can trigger the exploit. While specific Android versions or Pixel models affected have not been disclosed, users are advised to ensure they have the latest security patches to safeguard against potential malware attacks.

What some Apple flaws allowed

According to TASS, the nine vulnerabilities affecting Apple devices encompass issues related to elevated access rights, privacy breaches, and compromised data protection. One notable macOS flaw enables a malicious application to gain the highest level of control over the computer. Another vulnerability exposes sensitive information that the system typically safeguards, allowing access keys to be deleted without user approval.

Additionally, a flaw within the operating system’s kernel could lead to device failures or data corruption. Apple has released patches to address these vulnerabilities, although the company has not specified which operating system versions include these fixes. Devices that have not received updates remain at risk from the vulnerabilities described, particularly older models that no longer receive vendor support.

For Android users, checking the software version in system settings is essential to confirm the installation of the September 2026 patches. While neither Apple nor Google has officially acknowledged the report from Positive Technologies, the release of patches to rectify these flaws suggests the validity of the findings.

AppWizard
Sanctioned Russian firm identifies multiple security vulnerabilities in Android and Apple devices