CYBERSECURITY

Russian Cybersecurity Firm Uncovers Eleven Vulnerabilities in Google and Apple Devices

Russian Cybersecurity Firm Uncovers Eleven Vulnerabilities in Google and Apple Devices

Apple Security Breaches Expose User Data

A Russian cybersecurity company, ProSecurity, has identified eleven security weaknesses in products from Google and Apple. The discovery was announced on September 29, 2026, and the company is under international sanctions. The flaws span multiple operating systems and application layers.

The report details nine vulnerabilities that affect Apple devices, touching on access controls, privacy settings, macOS, and data protection mechanisms. Two additional flaws were found in Google’s ecosystem, one of which involves a malicious NFC tag that can compromise an Android device without user interaction. ProSecurity warned that the NFC flaw could trigger apps and install malware simply by tapping a tag.

The nine Apple flaws enable attackers to bypass authentication checks on iOS and macOS. Unauthorized users could read sensitive files, intercept communications, or gain root access. The vulnerabilities also affect privacy controls, allowing data leakage from apps that rely on sandboxing. ProSecurity’s analysis shows that the flaws could be exploited through crafted network traffic or malicious applications.

Android NFC Attack Raises Alarm

Security researchers say the Apple issues highlight gaps in the company’s sandboxing architecture. The flaws could allow attackers to escape from confined app environments and read system files. Users are urged to install the latest updates, which Apple has said will address the most critical weaknesses.

The NFC-based vulnerability is particularly concerning because it requires minimal user action. A single tap on a malicious tag can trigger code execution on an Android device. The flaw bypasses the operating system’s intent handling, allowing apps to run with elevated privileges. Google has acknowledged the issue and is working on a patch for the affected Android version.

The attack demonstrates how physical proximity can be exploited to bypass software defenses. Security experts recommend disabling NFC when not in use and avoiding unknown tags. Google’s response will likely involve a security update that tightens intent validation.

The findings underscore the ongoing battle between defenders and attackers. Both Apple and Google must prioritize patching these vulnerabilities to protect users. The sanctions on ProSecurity may limit direct collaboration, but the disclosure urges the industry to review its security practices. Users should keep devices updated and remain cautious about unfamiliar NFC tags.

Frequently Asked Questions

What is ProSecurity? ProSecurity is a Russian cybersecurity firm that provides vulnerability research and penetration testing services. The company is currently sanctioned by several governments.

How can users protect themselves from these vulnerabilities? Users should install the latest software updates from Apple and Google. They should also disable NFC when it is not needed and avoid interacting with unknown tags.

Will Apple and Google patch the flaws quickly? Both companies have announced plans to release security updates that address the identified weaknesses. Users should monitor official channels for patch releases and apply them promptly.

Content written by Efosa Udinmwen for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment