Google Confirms Critical Android 0-Click Vulnerability—Update Now

TL;DR AI
2 min readKey summary
Google’s May 2026 Android security bulletin flags a critical zero-click vulnerability, CVE-2026-0073, in an Android System component.
The flaw could let an adjacent-network attacker execute code as the shell user without any user interaction.
Google says the fix is included in security patch level 2026-05-01 or later, so devices should be updated immediately.
The issue affects Android 14, 15, 16, and 16-QPR2, making timely patching important for device security.



