Russian firm discovers critical security flaws in Android and Apple devices via NFC exploit

A sanctioned Russian cybersecurity firm has identified 11 security vulnerabilities affecting Android and Apple devices, with two Android flaws rated as high severity. One particularly dangerous flaw allows attackers to trigger app installations through NFC tags without owner approval, while another enables apps to modify network settings without additional permissions. Google has already patched both Android vulnerabilities in its September 2026 security updates.
The vulnerabilities discovered by Positive Technologies represent a spectrum of severity across both major mobile platforms. The Android flaws are particularly notable because they exploit fundamental device functions—NFC wireless communication and system permission architecture—to bypass user consent entirely. One vulnerability chains together tag reading with automatic app installation, while the other undermines the permission model by allowing installed applications to reconfigure network connectivity without triggering additional authorization prompts. Apple's nine identified flaws predominantly concern privilege escalation and data exposure, with one reaching kernel-level access that could destabilize system operations.
The timeline reveals an asymmetry in vendor response. Google moved quickly to address both Android issues within its standard monthly security cycle, making patches available immediately. Apple's disclosure of fixes remained vague regarding specific OS versions and rollout status, leaving uncertainty about which devices actually receive protection and when deployment occurs.
These findings could significantly impact users of both ecosystems who delay security updates or use older devices no longer receiving patches. The NFC exploit particularly may affect travelers and users in high-traffic areas where unknown tags proliferate. Device owners relying on automatic updates could face reduced risk, while enterprise environments managing fleet deployments may need to assess patch timing carefully. The discovery underscores how privileged access flaws in core system functions pose broader risks than isolated application vulnerabilities, potentially affecting millions of devices depending on adoption rates and user behavior.