Android users have been placed on red alert after a critical security flaw was discovered that could allow hackers to compromise devices without any action from the victim. The vulnerability, identified as CVE-2026-0073, has been given a zero-click rating, meaning cybercriminals can exploit it remotely without requiring users to click on links or download files.
Google confirmed the issue in its May Android Security Bulletin, stating: "This Android Security Bulletin contains details of security vulnerabilities that affect Android devices... The vulnerability in this section could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation."
The tech giant has rated the flaw as critical, and it is believed to exploit a debug interface that should never have been a production attack surface. Pixel phones will be the first to receive the patch, with other manufacturers such as Samsung expected to roll out their own updates shortly.
Adam Boynton, Senior Enterprise Strategy Manager at security firm Jamf, commented: "May’s Android security bulletin is light in volume but notable in shape. The single critical issue, CVE-2026-0073, allows remote code execution with no user interaction required... User awareness training does not defend against a vulnerability that requires no user interaction. The defences that work are device-level, including visibility into what is running, enforcement of patch state, and the recognition that the phone in an executive’s pocket is as much of an enterprise endpoint as the laptop on their desk."
All Android users are advised to check their device settings and ensure their software is fully up to date to protect against this serious threat.



