Google is urging Android users to install the latest security update after discovering a critical vulnerability that could allow attackers to compromise devices without requiring user interaction.
The flaw, tracked as CVE-2026-0073, affects Android 14, Android 15, and Android 16 devices, including newer interim releases. Google patched the issue in its May 1, 2026, Android security update, but users will only be protected once device manufacturers push the update to their phones.
CVE-2026-0073 is a zero-click vulnerability. Attackers do not need users to click a malicious link, download an app, or open a suspicious message.
Google said the flaw exists in a core component of Android and could potentially be exploited by attackers who are nearby or connected to the same network as the target device.
The vulnerability is linked to Android Debug Bridge, commonly known as ADB. This is a developer-focused tool that allows engineers to communicate with Android devices through a computer for testing and debugging purposes. The flaw allows attackers to abuse the interface in unintended ways.
One important detail here is that Google has already fixed the vulnerability. The bigger challenge is Android’s fragmented update ecosystem.
Unlike Apple, which pushes software updates directly to supported iPhones, Android updates depend heavily on smartphone manufacturers and carriers. Even after Google releases a patch, it can take days, weeks, or sometimes months for some devices to receive it.
Pixel devices are expected to receive the update first, while other brands will release patches gradually.
Google said it is not currently aware of active exploitation of CVE-2026-0073. However, the company recently confirmed that another Android vulnerability, CVE-2026-21385, had already been exploited in real-world attacks.
This is the reason security researchers are taking the new vulnerability seriously, even though no active attacks have been publicly confirmed yet.
If you own an Android device, install updates as soon as they become available.







