Android phone users under ‘high risk’, private photos and data can be leaked easily, Indian govt issues warning, here’s what you need to do

Android phone users in India have been issued a critical security warning after the Indian Computer Emergency Response Team (CERT-In) flagged multiple vulnerabilities affecting Android versions 14, 15, 16, 16 QPR2 and 17. The government agency warned that successful exploitation could allow attackers to execute malicious code, gain higher system privileges, disrupt devices or access sensitive information.

CERT-In published Vulnerability Note CIVN-2026-0454 on September 14, with the advisory covering both individual Android users and organisations. Google’s September Android security bulletin also confirms multiple critical vulnerabilities affecting these Android versions.

Android users facing multiple security risks

According to CERT-In, the vulnerabilities are present across several Android components, including Android Runtime, Documents UI, MediaTek Framework components, Media Codecs, MediaProvider, Telephonycore, UWB, and Wi-Fi.

The potential consequences include remote code execution, denial of service, privilege escalation and disclosure of sensitive information. In practical terms, an unpatched device could face unauthorised access to information or other forms of system compromise.

Google identifies critical flaws too

Google’s September 2026 Android Security Bulletin lists numerous critical vulnerabilities across the Framework and System components. Several are classified as remote code execution flaws, while others could allow privilege escalation or denial-of-service attacks.

Google says the most severe vulnerability in its September bulletin could enable remote code execution without requiring additional execution privileges or user interaction, although the impact depends on platform security protections and whether those protections are bypassed.

What Android phone users should do

The most important step is to install the latest security update available for your phone. Google says security patch levels dated September 1, 2026 or later address the vulnerabilities associated with that patch level.

Go to Settings > System > Software update or the equivalent software-update section on your phone and check for an update. Also install available Google Play system updates and restart the phone after the update if required.

Don’t ignore the warning

Not every Android phone will receive the update at the same time, as manufacturers and carriers determine their own rollout schedules. If your device is no longer receiving security updates, the CERT-In warning is a strong reason to consider moving to a supported device.

CERT-In has specifically advised affected users to apply the appropriate updates provided by the vendor.

 

Leave a Comment