Sanctioned billion-dollar cybersecurity company from Russia finds 11 vulnerabilities in Google and Apple products — including a nasty one that compromised a device just through a malicious NFC tag
Nine Apple vulnerabilities affected access controls, privacy, macOS, and data protection, while two Android flaws enabled dangerous system changes.
Russian cybersecurity firm Positive Technologies alleges it has uncovered 11 security flaws affecting Android and Apple devices, including one particularly dangerous issue discovered through NFC tags. The company, currently facing American sanctions, shared its findings with Russian news agency TASS. Nine vulnerabilities impacted Apple products and software, while two affected Android devices like Pixel phones, both rated as high severity.
The first Android flaw allowed attackers to use a crafted NFC tag to install and execute an app without the owner's approval. The second flaw enabled an app on the phone to alter network settings, including connecting to a chosen Wi-Fi network, without additional permissions. The NFC tag flaw is deemed especially hazardous due to the phone's proximity to the tag being enough to trigger the vulnerability.
Google patched both Android issues in its September 2026 updates, so devices with those patches should no longer be at risk. However, the specific Android versions or Pixel models vulnerable remain unknown, so users should ensure they have the latest security updates.
Regarding Apple devices, Positive Technologies reported nine flaws that increased the potential for attackers to gain higher system privileges, expose sensitive information, and weaken data protections. One macOS flaw granted hostile apps complete control over the computer, while another exposed protected system information. Additionally, a kernel-level flaw could cause a device to fail or corrupt memory data.
Apple has released fixes for these vulnerabilities, but older devices without updates remain exposed. Android users should verify their software version to ensure they have installed the September 2026 patches. While neither Google nor Apple commented on Positive Technologies' report, both promptly provided patches, suggesting the claims are credible.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Google confirms ChromeOS phase out in 2034 — 10-year support lifetime cut short for some devices, company says it will support transition to Googlebook OS tomshardware.com
- Google Says Chromebook Updates End In 2034, 'Many' Models Move to Googlebook OS tech.slashdot.org
- Google seemingly confirms plans to kill ChromeOS in 2034 arstechnica.com
- Even Google Search agrees that ‘Googlebook’ wasn’t a very good name choice 9to5google.com