LiMP VPN
← All news

Russian Researchers Found 11 Flaws in Google and Apple Products

Russian Researchers Found 11 Flaws in Google and Apple Products

In short: On September 25, 2026, it emerged that researchers at Russian security firm Positive Technologies (teams PT Maze and PT ESC) had found 11 vulnerabilities across Google and Apple products — two in Android/Google Pixel and nine across Apple's ecosystem (macOS and the iOS/Apple kernel). The most dangerous Android finding let an attacker use a specially crafted NFC tag to download, install, and launch an app without any confirmation from the device owner; a second flaw let an already-installed app silently change a device's network settings. Both were fixed in Android's September 2026 security update. The Apple issues involved privilege escalation, user-data protection, and a macOS kernel crash. The detail worth remembering: even a fully patched device is only safe until the next flaw is found — the real protection isn't a one-time update, it's the habit of installing updates promptly. For more on picking a genuinely secure service, see our piece on the most secure VPN.

What researchers actually found

According to Positive Technologies, researcher Alena Sklyarova (PT Maze) found two vulnerabilities in Android and Google Pixel devices. The first, CVE-2026-57012, rated high severity, let an attacker use a specially crafted NFC tag to trigger the download, installation, and launch of an app without any confirmation from the phone's owner — simply tapping the phone against an infected tag (embedded in a poster, sticker, or payment terminal, for example) was enough to compromise it. The second, CVE-2026-28616, also high severity, let an already-installed app change a phone's network settings without user permission: connect to Wi-Fi, install a certificate, or change proxy settings — potentially rerouting all of the device's traffic through a node the attacker controls.

Nine issues across Apple's ecosystem

Eight vulnerabilities in Apple products were found by researcher Ilya Andr (PT Maze), and one more by Mikhail Lozhnikov (PT ESC). Among the disclosed details: CVE-2026-43783 in macOS let a malicious app gain maximum system privileges — effectively full control over the device, bypassing standard restrictions. CVE-2026-65330 affected the Apple kernel and could cause a device crash or kernel memory corruption under certain conditions. The remaining seven vulnerabilities involved privilege escalation, privacy, and user-data protection, including a mechanism that let an app delete a user's saved passkeys without authorization.

Why the NFC-tag flaw is especially concerning

Unlike classic phishing or an infected file, an NFC attack asks almost nothing of the victim: no link to click, no password to enter, no "install from unknown sources" prompt to approve — a physical tap against an infected tag is enough. Such tags are easy to disguise as legitimate ones (in a café, a parking lot, on public transit, on a poster with a QR/NFC tag), and a user may never notice the compromise at all if the installed app doesn't behave visibly differently. Security researchers typically treat this "zero user action" class of vulnerability as one of the highest patching priorities.

What this means for everyday users

Both Android vulnerabilities are already fixed in the September 2026 security update — if auto-updates are enabled on a phone, the hole is likely already closed. The real problem is different: statistics show a significant share of users delay installing security updates for weeks or months, leaving their devices exposed to attack methods that are already public and potentially known to attackers. The network-settings flaw creates a separate risk on its own: if an app can silently connect a device to someone else's Wi-Fi network or swap out its proxy server, all unencrypted traffic could become visible to an outside observer. An extra layer of protection in that scenario comes from encrypting traffic at the VPN level — it doesn't remove the need for updates, but it limits the damage if network settings were compromised regardless. For more on how that protection works, see the LiMP VPN features page.

How to protect yourself right now

  • Check whether the September 2026 Android security update is installed (Settings → Security → System update), and enable auto-updates if they're off.
  • On Apple devices, confirm you're running the latest macOS/iOS version with current patches.
  • Avoid tapping your phone against unfamiliar NFC tags in public places, especially if a tag looks stuck on top of an official one (a common sign of tampering).
  • Periodically review the list of saved Wi-Fi networks and proxy settings on your device — unexpected entries can be a sign of compromise.
  • Use a VPN with encrypted traffic as an extra barrier in case a device's network settings were changed without your knowledge: for instance, LiMP VPN encrypts the connection regardless of which network the device is actually attached to.

Sources