<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Android Security</title><description>Cybersecurity articles tagged #Android Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Open-Source Android AI Agent Hijacking Leads to Host System RCE</title><link>https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</guid><description>Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.</description><pubDate>Tue, 21 Jul 2026 13:54:29 GMT</pubDate><category>Android Security</category><category>AI Agents</category><category>Prompt Injection</category><category>RCE</category><category>Mobile Security</category><category>Appagent</category></item><item><title>RedHook Android Malware: Abusing Wireless ADB for Local Shell Access</title><link>https://runtimerebel.com/blog/redhook-android-malware-abusing-wireless-adb-for-local-shell-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/redhook-android-malware-abusing-wireless-adb-for-local-shell-access</guid><description>RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.</description><pubDate>Sun, 12 Jul 2026 16:59:53 GMT</pubDate><category>RedHook</category><category>Android Security</category><category>ADB Exploitation</category><category>Mobile Threats</category><category>Wireless Debugging</category></item><item><title>Google Gemini Hijack: Command Injection via Messaging Notifications</title><link>https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-hijack-command-injection-via-messaging-notifications</guid><description>Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.</description><pubDate>Thu, 04 Jun 2026 13:16:24 GMT</pubDate><category>Google Gemini</category><category>Prompt Injection</category><category>Voice Assistant</category><category>Iot Security</category><category>Android Security</category></item><item><title>Google Gemini Hijacked on Android via Poisoned Notifications</title><link>https://runtimerebel.com/blog/google-gemini-hijacked-on-android-via-poisoned-notifications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-hijacked-on-android-via-poisoned-notifications</guid><description>Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.</description><pubDate>Wed, 03 Jun 2026 21:09:55 GMT</pubDate><category>Google Gemini</category><category>Android Security</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626</title><link>https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-and-linux-kernel-exploitation-cve-2024-36971-and-cve-2024-21626</guid><description>CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.</description><pubDate>Wed, 03 Jun 2026 17:46:16 GMT</pubDate><category>CVE-2024-36971</category><category>CVE-2024-21626</category><category>CISA KEV</category><category>Android Security</category><category>Linux Kernel</category><category>Container Breakout</category></item><item><title>CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595</title><link>https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-active-exploitation-of-cve-2022-0492-and-cve-2025-48595</guid><description>CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.</description><pubDate>Tue, 02 Jun 2026 21:13:18 GMT</pubDate><category>CVE-2022-0492</category><category>CVE-2025-48595</category><category>CISA KEV</category><category>Linux Kernel</category><category>Android Security</category></item><item><title>CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day</title><link>https://runtimerebel.com/blog/cve-2025-48595-android-june-2026-update-patches-exploited-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-48595-android-june-2026-update-patches-exploited-zero-day</guid><description>Google&apos;s June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.</description><pubDate>Tue, 02 Jun 2026 21:09:21 GMT</pubDate><category>CVE-2025-48595</category><category>Android Security</category><category>Google</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>Misconfigured MSAL for Android Exposes Microsoft Account Tokens</title><link>https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</guid><description>A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.</description><pubDate>Tue, 02 Jun 2026 17:39:32 GMT</pubDate><category>Microsoft</category><category>Android Security</category><category>Msal</category><category>Token Theft</category><category>Identity Management</category></item><item><title>Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users</title><link>https://runtimerebel.com/blog/android-intrusion-logging-enhancing-spyware-forensics-for-high-risk-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-intrusion-logging-enhancing-spyware-forensics-for-high-risk-users</guid><description>Google introduces Intrusion Logging for Android to capture persistent forensic data, aiding the detection of sophisticated spyware and state-sponsored attacks.</description><pubDate>Wed, 13 May 2026 09:08:56 GMT</pubDate><category>Android Security</category><category>Spyware Forensics</category><category>Google Advanced Protection</category><category>Mobile Threat Defense</category></item><item><title>7.3M Downloads: Analyzing Fraudulent Android Call History Apps</title><link>https://runtimerebel.com/blog/7-3m-downloads-analyzing-fraudulent-android-call-history-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/7-3m-downloads-analyzing-fraudulent-android-call-history-apps</guid><description>Researchers discover 28 fraudulent Android apps on the Google Play Store that trick millions of users into expensive, fraudulent subscriptions.</description><pubDate>Fri, 08 May 2026 16:36:22 GMT</pubDate><category>Android Security</category><category>Google Play Store</category><category>Fleeceware</category><category>Financial Fraud</category><category>Mobile Malware</category></item><item><title>Google Android Binary Transparency: Defending Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/google-android-binary-transparency-defending-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-binary-transparency-defending-against-supply-chain-attacks</guid><description>Google expands Binary Transparency to Android apps, providing a public ledger to verify app integrity and mitigate risks of mobile supply chain attacks.</description><pubDate>Wed, 06 May 2026 12:45:20 GMT</pubDate><category>Android Security</category><category>Binary Transparency</category><category>Google Play</category><category>App Integrity</category></item><item><title>Google Android VRP 2024 Updates: $1.5M for Pixel Kernel Exploits</title><link>https://runtimerebel.com/blog/google-android-vrp-2024-updates-1-5m-for-pixel-kernel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-vrp-2024-updates-1-5m-for-pixel-kernel-exploits</guid><description>Google overhauls its Vulnerability Rewards Programs, increasing payouts for complex Android exploits while devaluing bugs easily identified by AI tools.</description><pubDate>Tue, 05 May 2026 12:36:32 GMT</pubDate><category>Google VRP</category><category>Android Security</category><category>Pixel Titan M</category><category>Chrome Security</category><category>Bug Bounty</category></item><item><title>Google Adjusts Bug Bounties: $1.5M Android Reward and AI Shift</title><link>https://runtimerebel.com/blog/google-adjusts-bug-bounties-1-5m-android-reward-and-ai-shift</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-adjusts-bug-bounties-1-5m-android-reward-and-ai-shift</guid><description>Google updates its Vulnerability Reward Program, increasing Android zero-click payouts to $1.5 million while adjusting Chrome rewards amid an AI security surge.</description><pubDate>Fri, 01 May 2026 16:27:37 GMT</pubDate><category>Google VRP</category><category>Android Security</category><category>Pixel Titan M</category><category>AI Security</category><category>Chrome Security</category><category>Bug Bounty</category></item><item><title>EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass</title><link>https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/engagelab-sdk-vulnerability-protecting-crypto-wallets-from-sandbox-bypass</guid><description>A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.</description><pubDate>Fri, 10 Apr 2026 00:40:05 GMT</pubDate><category>EngageLab SDK</category><category>Android Security</category><category>Crypto Wallet Vulnerability</category><category>Microsoft Defender</category><category>Mobile Security</category></item><item><title>Exposed Google API Keys in Android Apps Grant Gemini Access</title><link>https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</guid><description>Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.</description><pubDate>Thu, 09 Apr 2026 12:47:35 GMT</pubDate><category>Google API Keys</category><category>Android Security</category><category>Gemini AI</category><category>API Security</category><category>Data Exposure</category><category>Misconfiguration</category></item><item><title>ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, &amp; Cloud Evasion</title><link>https://runtimerebel.com/blog/threatsday-bulletin-pre-auth-chains-android-rootkits-cloud-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/threatsday-bulletin-pre-auth-chains-android-rootkits-cloud-evasion</guid><description>Analysis of the latest ThreatsDay Bulletin covering critical pre-authentication exploit chains, stealthy Android rootkits, and advanced CloudTrail evasion techniques.</description><pubDate>Thu, 02 Apr 2026 16:25:58 GMT</pubDate><category>Pre Authentication</category><category>Exploit Chain</category><category>Android Security</category><category>Rootkit</category><category>Cloud Security</category><category>CloudTrail Evasion</category></item><item><title>Android Security Safeguards and UK Cyber Reporting Mandates</title><link>https://runtimerebel.com/blog/android-security-safeguards-and-uk-cyber-reporting-mandates</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-security-safeguards-and-uk-cyber-reporting-mandates</guid><description>Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.</description><pubDate>Fri, 20 Mar 2026 16:20:19 GMT</pubDate><category>Android Security</category><category>Operation Alice</category><category>UK Cyber Regulation</category><category>Ransomware</category><category>KVM Vulnerabilities</category></item><item><title>Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities</title><link>https://runtimerebel.com/blog/google-vrp-2025-17-1-million-paid-for-security-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-vrp-2025-17-1-million-paid-for-security-vulnerabilities</guid><description>Google&apos;s Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.</description><pubDate>Thu, 12 Mar 2026 16:29:22 GMT</pubDate><category>Google VRP</category><category>Android Security</category><category>Chrome Security</category><category>Bug Bounty</category><category>AI Security</category></item></channel></rss>