Back Heise.De Patchday: Critical malicious code vulnerability threatens Android 14, 15, and 16
To prevent attacks on smartphones and tablets with Android 14, 15, 16, and 16qpr2, owners of devices still under support should install the latest security update. In addition to Google's Pixel series, it is also available for selected devices from Samsung, among others (see box).
Support for Android 13 ended in March of this year, and this version has not received security patches since then. Millions of devices are affected by this.
If attackers exploit a – critical – security vulnerability (CVE-2026-0073) in the adbd debugging module, they can remotely execute malicious code, the developers explain in a warning message . Typically, systems are then considered fully compromised. How such an attack could occur is currently unclear. So far, there are no indications from Google that attackers are already exploiting the vulnerability. The developers state that they have resolved the security problem in Patch Level 2026-05-01 .
In July 2025, Google decided to only close security vulnerabilities deemed particularly dangerous according to its assessment on the monthly Android Patchday. Further patches have followed quarterly since then.
Neben Google veröffentlichen noch weitere Hersteller regelmäßig Sicherheitspatches - aber meist nur für einige Produktserien. Geräte anderer Hersteller bekommen die Updates erheblich später oder, im schlimmsten Fall, gar nicht.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
