• Sanctioned billion-dollar cybersecurity company from Russia finds

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 29, 2026 22:30:22
    Sanctioned billion-dollar cybersecurity company from Russia finds 11 vulnerabilities in Google and Apple products including a nasty one that compromised a device just through a malicious NFC tag

    Date:
    Tue, 29 Sep 2026 21:15:00 +0000

    Description:
    Nine Apple vulnerabilities affected access controls, privacy, macOS, and data protection, while two Android flaws enabled dangerous system changes.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter A macOS flaw could give hostile apps the highest system privileges An NFC tag could trigger an Android app without owner approval Android flaw lets apps change Wi-Fi settings without requesting extra permissions Russian cybersecurity firm Positive Technologies has claimed it discovered 11 security flaws affecting Android and Apple devices.

    The company, which is currently under American sanctions, gave the findings
    to Russian news agency TASS . Nine of the flaws affected Apple devices and software, while two affected Android, including Pixel phones, and were reportedly rated high severity. Latest Videos From TechRadar Watch full video here: How a tag and an app exposed Android phones The first Android flaw let attackers use a crafted NFC tag to fetch, set up, and run an app while the owner approved nothing.

    The second flaw allowed an app already on the phone to alter network
    settings, including joining a chosen Wi-Fi network, without any extra permissions, and also let the app add a certificate or adjust proxy parameters, and neither action required the phone owner to confirm anything. You may like 'Decades-old' bugs found affecting Windows, Android, macOS and Linux but the OS makers don't see it as a big deal Apple patches
    CoreGraphics zero-day used in 'extremely sophisticated' targeted attacks on iOS devices Samsung patches nearly 200 security issues on its phone hardware
    - here's what you need to know

    Google resolved both Android flaws in its September 2026 patches, so devices which have installed those patches should no longer face either problem.

    The company describes the tag flaw as especially hazardous since holding a phone near the tag suffices to trigger it. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    There was no mention of specific Android versions or Pixel models that were vulnerable, so the number of exposed devices remains unknown, but to be safe from malware attacks, get the latest security patch. What some Apple flaws allowed According to TASS , the nine Apple flaws covered higher access
    rights, privacy exposure, and weakened data safeguards.

    One macOS flaw allowed a hostile app to obtain the highest level of control over the computer, and another exposed information the system normally protects. The keys used for access could be deleted without the user
    approving the action. What to read next A potentially dangerous macOS
    security flaw went unreported due to Apple being deluged by AI slop bug reports Experts build WeChat worm able to spread across millions of iPhone
    and Android devices via phone calls Apple and Google are hosting hundreds of dangerous VPN links here is why your device is at risk

    Another flaw was found inside the kernel of the operating system and could cause a device to fail or corrupt data held in memory.

    Apple has released patches for the flaws, although the company did not say which operating system versions carry the fix.

    Devices that never received an update stay exposed to every flaw the firm described, whatever patches the vendors have issued.

    Owners of older phones and computers that no longer receive vendor updates face the most uncertainty, because a fix never reaches them.

    Android owners should check their software version in system settings to confirm the September 2026 patches arrived on their devices.

    Neither Apple nor Google acknowledged the Positive Technologies report as expected, but they both released patches fixing these flaws, which implies that the report is legitimate.

    Via 1.ru Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/sanctioned-billion-dollar-cybersecurity-company- from-russia-found-11-vulnerabilities-in-google-and-apple-products-including-a- nasty-one-that-compromised-a-device-just-through-a-malicious-nfc-tag


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)