logo

Critical Android Flaw Allows Zero-Interaction Denial-of-Service Attacks

ID: 90afa430-5505-5f2b-a7bd-537a094675f9

STIX ID: report--90afa430-5505-5f2b-a7bd-537a094675f9

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Divya

...
...

Google's April 2026 Android Security Bulletin fixes a critical zero-click Framework denial-of-service vulnerability (CVE-2026-0049) that can crash devices without user interaction and a high-severity StrongBox hardware keystore vulnerability (CVE-2025-48651) affecting multiple vendors (Google, NXP, STMicroelectronics, Thales); users are advised to apply the 2026-04-05 patch level (with 2026-04-01 addressing the Framework issue) to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.