mobile security3 articles
Google Quietly Patches Exploited Pixel Modem Flaw — No Click Required
Google has patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem, which has been found under limited, targeted exploitation in the wild. The vulnerability stems from a logic error that allows remote attackers to bypass permissions without any user interaction, making it exploitable as a silent zero-click attack. The fix is included in the September 2026 Pixel security update, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply patches by September 19, 2026.
Bixby as a Backdoor: How Two Researchers Chained Samsung's Own Apps Into a Full Device Takeover
Two security researchers from Microsoft and Mobile Hacking Lab discovered a chain of vulnerabilities in Samsung software — including the Bixby virtual assistant, Samsung Members, and Samsung Account — that could allow attackers to achieve system-level control of a Samsung Galaxy device. The exploit begins with a malicious link and chains multiple CVEs to ultimately abuse Bixby's internal "Capsule" infrastructure, enabling data exfiltration and remote code execution. Samsung has since patched the flaws, but older devices that haven't received updates remain at risk; the researchers demonstrated the attack successfully on Galaxy S24, S25, and Flip 7 models and won $50,000 at the Pwn2Own Ireland competition.
NFCShare Malware Evolves: Fake Banking App Updates Delivered Via GitHub
A new Android malware called NFCShare is being distributed through fake banking app updates hosted on GitHub, targeting customers of banks primarily in Italy and Spain. The malware tricks victims into scanning their payment cards near their phone's NFC chip under the guise of a security verification, stealing card details and PINs which are then sent to attackers for use in NFC payment relay fraud. Android users are advised to only download banking apps from Google Play, enable Play Protect, and be wary of any requests to scan their cards through an app.