<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Android</title><description>Cybersecurity articles tagged #Android on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN</title><link>https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</link><guid isPermaLink="true">https://runtimerebel.com/blog/toxicpanda-2-0-android-malware-abuses-wireless-adb-and-vpn</guid><description>ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.</description><pubDate>Sun, 23 Aug 2026 16:15:53 GMT</pubDate><category>ToxicPanda</category><category>Android</category><category>Malware</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Android Car Head Unit Malware Spreads via Built-In Updaters</title><link>https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</guid><description>Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.</description><pubDate>Sat, 22 Aug 2026 16:13:11 GMT</pubDate><category>Malware</category><category>Android</category><category>Ad Fraud</category><category>Botnet</category></item><item><title>Unisoc Modem Exploit Chain: Android Takeover via Video Call</title><link>https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</link><guid isPermaLink="true">https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</guid><description>An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.</description><pubDate>Tue, 18 Aug 2026 00:41:53 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Remote Code Execution</category><category>Exploit Chain</category><category>Unisoc</category></item><item><title>Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience</title><link>https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</guid><description>Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.</description><pubDate>Tue, 11 Aug 2026 16:52:19 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Android</category><category>DDoS</category><category>IoT</category></item><item><title>Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder</title><link>https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</guid><description>Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.</description><pubDate>Sat, 08 Aug 2026 08:35:48 GMT</pubDate><category>Google Pixel</category><category>CVE-2025-54957</category><category>Zero-Day</category><category>Remote Code Execution</category><category>Android</category></item><item><title>Project Zero Uncovers Android 0-Click Exploit Chain Ecosystem Weaknesses</title><link>https://runtimerebel.com/blog/project-zero-uncovers-android-0-click-exploit-chain-ecosystem-weaknesses</link><guid isPermaLink="true">https://runtimerebel.com/blog/project-zero-uncovers-android-0-click-exploit-chain-ecosystem-weaknesses</guid><description>Project Zero details findings from a Pixel 9 0-click exploit chain, highlighting critical Android ecosystem issues and proposing security enhancements.</description><pubDate>Sat, 08 Aug 2026 01:01:55 GMT</pubDate><category>Android</category><category>Driver Security</category><category>Pixel 9</category><category>Project Zero</category><category>CVE-2025-54957</category></item><item><title>Fake Bahrain Alert Apps Deploy Android Surveillance Malware</title><link>https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-bahrain-alert-apps-deploy-android-surveillance-malware</guid><description>Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…</description><pubDate>Wed, 22 Jul 2026 21:12:30 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Spyware</category><category>Surveillance Malware</category><category>Fake Apps</category><category>Phishing</category><category>Social Engineering</category><category>Bahrain</category></item><item><title>RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis</title><link>https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/redwing-maas-android-bank-fraud-via-telegram-rental-service-analysis</guid><description>RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.</description><pubDate>Tue, 07 Jul 2026 18:01:20 GMT</pubDate><category>RedWing</category><category>MaaS</category><category>Android</category><category>Banking Malware</category><category>Oblivion</category><category>Telegram</category><category>Mobile Security</category></item><item><title>CVE-2026-46242: Linux Kernel Bad Epoll Flaw Grants Root on Servers, Android</title><link>https://runtimerebel.com/blog/cve-2026-46242-linux-kernel-bad-epoll-flaw-grants-root-on-servers-android</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-46242-linux-kernel-bad-epoll-flaw-grants-root-on-servers-android</guid><description>Critical Linux kernel &apos;Bad Epoll&apos; flaw (CVE-2026-46242) allows unprivileged users to gain root access on servers, desktops, and Android devices. Patch now.</description><pubDate>Fri, 03 Jul 2026 21:09:03 GMT</pubDate><category>CVE-2026-46242</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>Android</category><category>Bad Epoll</category><category>Local Root</category></item><item><title>Google&apos;s €4.1B EU Fine Stands: Android Antitrust Implications</title><link>https://runtimerebel.com/blog/google-s-eur4-1b-eu-fine-stands-android-antitrust-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-s-eur4-1b-eu-fine-stands-android-antitrust-implications</guid><description>Google loses final appeal against its €4.1 billion EU antitrust fine concerning Android&apos;s dominance. Understand the compliance implications for tech giants.</description><pubDate>Thu, 02 Jul 2026 17:54:31 GMT</pubDate><category>Google</category><category>Android</category><category>EU</category><category>Antitrust</category><category>Compliance</category><category>Regulatory</category><category>CJEU</category><category>Competition Law</category></item><item><title>AirDrop and Quick Share: Proximity Flaws Cause Crashes and Bypass Checks</title><link>https://runtimerebel.com/blog/airdrop-and-quick-share-proximity-flaws-cause-crashes-and-bypass-checks</link><guid isPermaLink="true">https://runtimerebel.com/blog/airdrop-and-quick-share-proximity-flaws-cause-crashes-and-bypass-checks</guid><description>Researchers found six security flaws in AirDrop and Quick Share, enabling nearby attackers to crash devices and bypass security checks without user interaction.</description><pubDate>Tue, 30 Jun 2026 12:49:12 GMT</pubDate><category>AirDrop</category><category>Quick Share</category><category>macOS</category><category>iOS</category><category>Android</category><category>Wireless Security</category><category>Proximity Attack</category><category>Denial of Service</category><category>Privacy Bypass</category></item><item><title>Google Android Scam Detection: Real-Time AI Defense Against Fraud</title><link>https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-scam-detection-real-time-ai-defense-against-fraud</guid><description>Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.</description><pubDate>Wed, 03 Jun 2026 09:44:39 GMT</pubDate><category>Android</category><category>Google Gemini Nano</category><category>AI Deepfakes</category><category>Vishing</category><category>Mobile Security</category></item><item><title>Android June 2024 Update: CVE-2024-32896 Zero-Day Exploit Patched</title><link>https://runtimerebel.com/blog/android-june-2024-update-cve-2024-32896-zero-day-exploit-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-june-2024-update-cve-2024-32896-zero-day-exploit-patched</guid><description>Google fixes 124 vulnerabilities including an actively exploited Pixel firmware zero-day and critical RCE flaws in the June 2024 Android security update.</description><pubDate>Tue, 02 Jun 2026 13:27:26 GMT</pubDate><category>Android</category><category>CVE-2024-32896</category><category>Pixel</category><category>Google</category><category>Zero-Day</category><category>Privilege Escalation</category></item><item><title>Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests</title><link>https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</link><guid isPermaLink="true">https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</guid><description>Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.</description><pubDate>Tue, 19 May 2026 20:39:59 GMT</pubDate><category>Android</category><category>Ad Fraud</category><category>Trapdoor</category><category>HUMAN Satori</category><category>Malvertising</category></item><item><title>Pixel 10 0-Click Exploit Chain: Re-Targeting CVE-2025-54957 for Root</title><link>https://runtimerebel.com/blog/pixel-10-0-click-exploit-chain-re-targeting-cve-2025-54957-for-root</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-10-0-click-exploit-chain-re-targeting-cve-2025-54957-for-root</guid><description>Analysis of a zero-click exploit chain targeting the Google Pixel 10, achieving root via an adapted Dolby vulnerability (CVE-2025-54957). Critical threat. Patch now.</description><pubDate>Wed, 13 May 2026 20:40:26 GMT</pubDate><category>Pixel 10</category><category>Android</category><category>Zero Click</category><category>CVE-2025-54957</category><category>Exploit Chain</category><category>RET PAC</category><category>Root Exploit</category></item><item><title>Android CVE-2026-0073: Critical System RCE Patch Guidance</title><link>https://runtimerebel.com/blog/android-cve-2026-0073-critical-system-rce-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-cve-2026-0073-critical-system-rce-patch-guidance</guid><description>Google addresses a critical zero-click RCE vulnerability (CVE-2026-0073) in the Android System component. Learn how to mitigate this high-impact security flaw.</description><pubDate>Tue, 05 May 2026 12:37:20 GMT</pubDate><category>CVE-2026-0073</category><category>Android</category><category>RCE</category><category>Zero Click</category><category>Google</category></item><item><title>Android Dirty Stream Path Traversal: Detecting and Patching App Exploits</title><link>https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-dirty-stream-path-traversal-detecting-and-patching-app-exploits</guid><description>Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.</description><pubDate>Mon, 20 Apr 2026 05:08:30 GMT</pubDate><category>Android</category><category>Dirty Stream</category><category>Path Traversal</category><category>Mobile Security</category><category>Microsoft Threat Intelligence</category></item><item><title>CVE-2024-21390: EngageLab SDK Vulnerability Risks Android Crypto Wallets</title><link>https://runtimerebel.com/blog/cve-2024-21390-engagelab-sdk-vulnerability-risks-android-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21390-engagelab-sdk-vulnerability-risks-android-crypto-wallets</guid><description>Microsoft reveals a vulnerability in the EngageLab SDK affecting millions of Android crypto wallet users, potentially allowing for private key theft.</description><pubDate>Fri, 10 Apr 2026 08:39:29 GMT</pubDate><category>CVE-2024-21390</category><category>Android</category><category>EngageLab</category><category>Cryptocurrency</category><category>SDK Vulnerability</category></item><item><title>Android StrongBox DoS Vulnerability Patched – Update Now</title><link>https://runtimerebel.com/blog/android-strongbox-dos-vulnerability-patched-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-strongbox-dos-vulnerability-patched-update-now</guid><description>A critical Denial-of-Service vulnerability in Android&apos;s StrongBox keymaster and Framework component has been patched. Immediate updates are crucial for device security.</description><pubDate>Tue, 07 Apr 2026 16:29:56 GMT</pubDate><category>Android</category><category>StrongBox</category><category>DoS</category><category>Vulnerability</category><category>Patch</category><category>Mobile Security</category></item><item><title>SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases</title><link>https://runtimerebel.com/blog/sparkcat-mobile-malware-variant-steals-crypto-recovery-phrases</link><guid isPermaLink="true">https://runtimerebel.com/blog/sparkcat-mobile-malware-variant-steals-crypto-recovery-phrases</guid><description>A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.</description><pubDate>Fri, 03 Apr 2026 12:21:17 GMT</pubDate><category>SparkCat</category><category>Mobile Malware</category><category>iOS</category><category>Android</category><category>Cryptocurrency Theft</category><category>App Store Malware</category><category>Recovery Phrase Theft</category></item><item><title>NoVoice Android Malware on Google Play: 2.3 Million Devices Infected</title><link>https://runtimerebel.com/blog/novoice-android-malware-on-google-play-2-3-million-devices-infected</link><guid isPermaLink="true">https://runtimerebel.com/blog/novoice-android-malware-on-google-play-2-3-million-devices-infected</guid><description>NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.</description><pubDate>Wed, 01 Apr 2026 20:19:41 GMT</pubDate><category>Android</category><category>NoVoice</category><category>Google Play</category><category>Adware</category><category>Malware</category><category>Mobile Security</category></item><item><title>Android Developer Identity Verification: New Google Play Mandates</title><link>https://runtimerebel.com/blog/android-developer-identity-verification-new-google-play-mandates</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-developer-identity-verification-new-google-play-mandates</guid><description>Google mandates identity verification for all Android developers to reduce malicious app distribution and improve Play Store transparency starting September.</description><pubDate>Tue, 31 Mar 2026 20:17:58 GMT</pubDate><category>Android</category><category>Google Play</category><category>Identity Verification</category><category>Mobile Security</category><category>Developer Compliance</category></item><item><title>Google Play Protect Advanced Flow for Android Sideloading</title><link>https://runtimerebel.com/blog/google-play-protect-advanced-flow-for-android-sideloading</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-play-protect-advanced-flow-for-android-sideloading</guid><description>Google introduces Advanced Flow to Play Protect, enhancing security for Android sideloading to combat financial fraud and malicious APK installations.</description><pubDate>Sat, 21 Mar 2026 16:09:55 GMT</pubDate><category>Android</category><category>Google Play Protect</category><category>Sideloading</category><category>Mobile Security</category><category>Fintech Fraud</category></item><item><title>Google Android Security: 24-Hour Wait for Unverified Sideloading</title><link>https://runtimerebel.com/blog/google-android-security-24-hour-wait-for-unverified-sideloading</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-android-security-24-hour-wait-for-unverified-sideloading</guid><description>Google introduces a mandatory 24-hour cooling-off period for sideloading unverified Android applications to mitigate malware and financial scams.</description><pubDate>Fri, 20 Mar 2026 12:17:05 GMT</pubDate><category>Android</category><category>Google Play Protect</category><category>Sideloading</category><category>Malware Prevention</category><category>Mobile Security</category></item><item><title>Perseus Android Malware: Technical Analysis of Note-Stealing Tactics</title><link>https://runtimerebel.com/blog/perseus-android-malware-technical-analysis-of-note-stealing-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/perseus-android-malware-technical-analysis-of-note-stealing-tactics</guid><description>Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.</description><pubDate>Thu, 19 Mar 2026 12:19:37 GMT</pubDate><category>Android</category><category>Perseus</category><category>Credential Theft</category><category>Mobile Security</category><category>Accessibility Services</category></item><item><title>BeatBanker Android Malware: Starlink Impersonation &amp; Device Hijack</title><link>https://runtimerebel.com/blog/beatbanker-android-malware-starlink-impersonation-device-hijack</link><guid isPermaLink="true">https://runtimerebel.com/blog/beatbanker-android-malware-starlink-impersonation-device-hijack</guid><description>New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection &amp; mitigation.</description><pubDate>Wed, 11 Mar 2026 00:32:24 GMT</pubDate><category>BeatBanker</category><category>Android</category><category>Malware</category><category>Starlink</category><category>Mobile Security</category><category>Sideloading</category><category>Banking Malware</category></item><item><title>Security Flaws in Android Mental Health Apps Affect 14.7M Users</title><link>https://runtimerebel.com/blog/security-flaws-in-android-mental-health-apps-affect-14-7m-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-flaws-in-android-mental-health-apps-affect-14-7m-users</guid><description>Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.</description><pubDate>Tue, 24 Feb 2026 08:20:26 GMT</pubDate><category>Android</category><category>Data Privacy</category><category>Mental Health Apps</category><category>Hard Coded Credentials</category><category>API Security</category><category>Paii</category></item></channel></rss>