The Russian cybersecurity company discovers serious vulnerabilities that affect both Android and Apple devices
- A macOS bug could give hostile apps the highest system privileges
- An NFC tag could activate an Android app without owner approval
- Android bug allows apps to change Wi-Fi settings without requesting additional permissions
Russian cybersecurity company Positive Technologies claimed to have discovered 11 security flaws affecting Android and Apple devices.
The company, which is currently under US sanctions, communicated its findings to the Russian news agency. TAS.
Nine of the flaws affected Apple devices and software, while two affected Android, including Pixel phones, and were reportedly rated high severity.
Latest videos ofTechnologyRadar
How a sticker and an app exposed Android phones
The first Android flaw allowed attackers to use a designed NFC tag to find, configure, and run an app without the owner approving anything.
The second flaw allowed an app already on the phone to alter network settings, including joining a chosen Wi-Fi network, without any additional permissions, and also allowed the app to add a certificate or adjust proxy settings, with neither action requiring the phone’s owner to confirm anything.
Google resolved both Android flaws in its September 2026 patches, so devices that have installed those patches should no longer face either issue.
The company describes the tag defect as especially dangerous since simply holding a phone near the tag is enough to activate it.
No specific Android version or Pixel model was mentioned as being vulnerable, so the number of exposed devices is unknown, but to stay safe from malware attacks, get the latest security patch.
What some Apple failures allowed
According TASApple’s nine failures covered increased access rights, privacy exposure and weakened data protection.
One macOS flaw allowed a hostile application to gain the highest level of control over the computer and another exposed information that the system normally protects. Keys used for access could be deleted without the user approving the action.
Another flaw has been found within the operating system kernel and could cause a device to crash or corrupt data stored in memory.
Apple has released patches for the flaws, although the company did not say which operating system versions have the fix.
Devices that never received an update are exposed to all of the flaws the company described, regardless of which patches vendors have issued.
Owners of older phones and computers who no longer receive updates from carriers face the most uncertainty, because a solution never reaches them.
Android owners should check their software version in system settings to confirm that the September 2026 patches have arrived on their devices.
Neither Apple nor Google acknowledged the Positive Technologies report as expected, but both released patches to fix these flaws, implying that the report is legitimate.
Via 1.ru
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment