News Updated 6 days ago
Qualcomm patches 11 Snapdragon flaws: CVE-2026-25289 needs no login and no tap
SecurityMobile
Qualcomm published 11 vulnerabilities in Snapdragon and related chips on August 4. The heaviest sits in the Wi-Fi feature that discovers nearby devices, and works from within radio range with no login and no action by the user. No exploitation has been reported. Affected lists split by generation, and rollout timing is set by each handset maker.
2026.08.057 views
News Updated 7 days ago
LINE for Android: viewing a profile could run code (CVE-2026-16881)
MobileJapanese CompaniesSecurity
A crafted LINE profile could run code with the app's privileges on Android. The vendor rates it 8.7. The fix shipped in 26.7.2 in early summer; how to check yours.
2026.08.0414 views
News Updated 7 days ago
8 flaws in the chip inside four phones sold in Japan (CVE-2026-21548)
MobileSecurity
UNISOC disclosed eight chip flaws on August 1, 2026. The T8100 ships in four phones sold in Japan. All eight only cut connectivity, but no patch date exists.
2026.08.0314 views
News
Three Galaxy flaws exploitable with no user action, fixed in the July update (CVE-2026-21047)
SecurityMobile
Samsung's July 2026 Galaxy update fixes three flaws exploitable with no user action. Two sit in the same image codec that spyware exploited last year.
2026.07.285 views
News
Credit cards went down across Japan on July 16: convenience stores and Suica top-ups hit — the cause was an international card network outage
MobileJapanese CompaniesInfrastructure
On the morning of July 16, 2026, credit card payments briefly failed at convenience stores, drugstores, and station ticket machines across Japan, and Mobile Suica and PASMO top-ups were hit too. The cause was a failure in the international payment network linking card companies; it recovered by midday. Cash and already-charged balances still worked. Here is what happened, in order.
2026.07.1691 views
News
LINE for iOS bug can freeze your iPhone via a link (CVE-2026-3861)
MobileSecurityJapanese Companies
LINE for iPhone flaw (CVE-2026-3861): a crafted link fills the screen with pop-ups and briefly freezes the device. No data stolen. Update to 26.3.0 to fix.
2026.07.1315 views
News
Cheap Wi-Fi Cameras and Doorbells Can Be Hijacked, No Fix Coming: CVE-2026-28742
SecurityMobilePrivacy
Cheap Wi-Fi cameras and doorbells sold on Temu and Amazon (Naxclow / V720, X3) have a flaw that lets a stranger hijack the camera with no login, and CISA has issued an advisory. Your Wi-Fi password leaks too, and there is no patch. Here is CVE-2026-28742 and what owners should do.
2026.06.1328 views
News
Aqara Smart Locks and Cameras Could Be Hijacked: Cloud Flaws Including CVE-2026-50083
PrivacySecurityMobile
Researchers disclosed 10 vulnerabilities in Aqara's smart-home cloud, including CVE-2026-50083, that let an unauthenticated attacker operate smart locks and cameras. Here is the takeover chain and what owners should do.
2026.06.13101 views
News
Mitsubishi Electric Wi-Fi Appliance Vulnerability: Current Status, Safe Versions and What to Check
SecurityMobileJapanese Companies
Mitsubishi Electric disclosed CVE-2025-49604 affecting a wide range of Wi-Fi-enabled home appliances — air conditioners, refrigerators, rice cookers, IH cooktops and more. A device on the same Wi-Fi sending crafted traffic can temporarily halt the appliance's Wi-Fi, blocking smartphone remote control. There is no risk of data theft or takeover, but affected models should update to the fixed firmware.
2026.06.1127 views
News
Chrome and Edge V8 Zero-Day: Fixed Versions and Current Status
SecurityMobileGlobal Companies
Google Chrome, the world's most-used browser, has a serious flaw already used in attacks (CVE-2026-11645), and an emergency fix is out. Opening a trap page alone can hand over your device, and this is the fifth such case in 2026. All Chrome users are affected, as are Edge and Brave. Update to 149.0.7827.103 now. Here's how to check and what's affected.
2026.06.1037 views
News
Ivanti Sentry CVE-2026-10520 Exploited (KEV): Patch the 10.0 RCE Now
MobileSecurityInfrastructure
A flaw lets attackers remotely take over Ivanti Sentry — the gateway between staff phones and corporate email — with no password (CVE-2026-10520, severity 10.0). Paired with an authentication-bypass flaw that creates administrators at will (CVE-2026-10523), it requires an update to R10.5.2 / R10.6.2 / R10.7.1. The product has been attacked repeatedly before. Here are the affected versions and what to do now.
2026.06.1033 views
News
Docomo phones won't connect: morning outage reports, carrier says "not equipment failure"
InfrastructureMobileJapanese Companies
NTT Docomo acknowledged on the morning of May 19 that social-media complaints about mobile service difficulties have been increasing. Users report being out of service since before 4 a.m. and unable to connect for more than eight hours. Docomo says no equipment failure has been confirmed and is still investigating as of 11:30 a.m. Cause and recovery timeline are unknown.
2026.05.19124 views