India’s cybersecurity agency, CERT-In, has raised an alarm for Android smartphone owners, assigning a “critical” severity rating to a cluster of newly-uncovered vulnerabilities inside Google’s mobile operating system. The security note, designated CIVN-2026-0454 and released on September 14, warns that the weaknesses leave users’ mobile phones open to severe security breaches, including remote hacking, service outages and data theft. The warning directly applies to all individual consumers as well as enterprise organisations running hardware on the impacted operating systems.“Multiple vulnerabilities have been identified in Android which could be exploited by an attacker to execute arbitrary code causing denial of service, privilege escalation or disclosure of sensitive information on the targeted system,” Cert-In said.“Risk of remote code execution, denial of service, privilege escalation and sensitive information disclosure. Potential compromise of system, service disruption and unauthorized access to sensitive information,” the agency added.
Which Android OS version are affected
The alert flags multiple generations of the mobile operating system, leaving a wide range of devices exposed. These include: Android 14, Android 15, Android 16, Android 16-qpr2 and Android 17. The critical flaws stem from programming bugs scattered across core device operations and hardware interfaces.According to the release notes, vulnerabilities sit within the main Android runtime engine and the Documents UI. Security loopholes exist inside Telephonycore, standard Wi-Fi modules and Ultra-Wideband (UWB) wireless controllers. Additionally, bugs compromise MediaProvider directories, onboard Media Codecs and MediaTek Framework software components.If cybercriminals successfully take advantage of these software holes, the operational consequences for targets are severe.An attacker could remotely run arbitrary code on a targeted handset without needing physical control of the device. Beyond running unauthorized software, attackers can trigger complete denial-of-service conditions to disable phone functions, bypass standard permissions to gain administrative privileges, and secretly extract private, sensitive user records.
How to protect yourself
- Google has rolled out a security patch to fix the underlying flaws.
- Open Settings on your phone or tablet.
- Go to System
- Tap software update
- Your phone will automatically check for the latest update and download it.
- Restart to complete the installation
Click Here For The Original Source.
