Critical Android Flaw CVE-2026-0073: Your Phone Can Be Hacked Without You Doing Anything β Update Now
π€ What exactly is this flaw?
CVE-2026-0073 affects the Android Debug Bridge (ADB) component β a tool built into every Android phone that normally lets developers debug their apps. The flaw stems from a logic error in this component's authentication system.
In practice: a hacker on the same WiFi network can bypass authentication and send commands directly to your phone. They don't need you to click a link, download an app or approve anything. This is what's called a "zero-click" vulnerability β zero clicks required.
- You're in a cafΓ©, hotel or airport connected to public WiFi
- A hacker is on the same network β scanning for vulnerable Android devices
- They exploit the ADB flaw with nothing visible on your screen
- They can access your files, install apps, read your messages
- All within seconds β with no visible sign on your phone
π± Which phones are affected?
All Android phones that haven't yet received the May 1, 2026 security patch are vulnerable. This includes hundreds of millions of Samsung Galaxy, Google Pixel, Xiaomi, OnePlus and other devices.
β How to update your phone now
-
π± Google PixelSettings β System β System update
The May 2026 patch should appear as available. -
π± Samsung GalaxySettings β Software update β Download and install
The corresponding One UI update fixes CVE-2026-0073. -
π± Xiaomi / OPPO / OnePlusSettings β About phone β System updates
Timelines vary by manufacturer β check regularly. -
β VerificationSettings β About phone β Android security patch level
If you see "May 1, 2026" or later, you're protected.
- Avoid public WiFi until updated β cafΓ©, hotel, airport, train station
- Disable wireless debugging if enabled: Settings β Developer options β Wireless debugging
- Use your mobile data instead of public WiFi in the meantime
- Check daily whether an update is available for your model
- The affected component (ADB) is part of Android's Project Mainline
- Google can push the fix directly via the Google Play Store, without waiting for the manufacturer
- Also check: Play Store β Menu β Play System updates
- This allows fixing the flaw even on phones whose manufacturer is slow to deploy updates
- Enable automatic updates on your Android
- Never use public WiFi without a VPN
- Check your security patch level once a month
- If your phone is no longer updated by its manufacturer β it's time to change it
Not sure if your Android phone is protected?
Describe your situation to CyberGuard β it'll guide you through checking whether you're protected.
π€ Talk to CyberGuard β