Android phones vulnerable to remote hacking — update right now

Green skull on smartphone screen.
(Image credit: Shutterstock)

If you own one of the best Android phones you should update immediately, as Google has released fixes for three serious vulnerabilities—including one that is currently being exploited in the wild by hackers.

In its April 2023 Android security bulletin, the search giant announced security updates that contain fixes for two critical remote code execution (RCE) vulnerabilities as well as for one high severity vulnerability hackers are already using in their attacks.

These security flaws impact Android 11, Android 12, Android 12L and Android 13 and it’s highly recommended that users update their smartphones as soon as possible. Android partners like Samsung, OnePlus, Motorola and others are notified about issues like this at least one month before Google issues a security bulletin, which means patches for their devices are likely already available or will be rolled out soon.

Executing remote code and escalating system privileges

The first vulnerability (tracked as CVE-2023-21085) exists in Android’s System component and if exploited, it could allow an attacker to execute arbitrary code remotely. According to a blog post from Malwarebytes, this flaw involves improper input validation within the System component. 

To attack those who haven’t updated their smartphones with the latest patches yet, an attacker could trick them into opening a specially crafted file through a phishing attack.

Likewise, the second vulnerability (tracked as CVE-2023-21096) also exists in Android’s System component and just like with the first one, could allow an attacker to execute arbitrary code remotely.

The third vulnerability (tracked as CVE-2022-38181) was found in the Arm Mali GPU kernel driver and has been used in targeted attacks since it was first discovered in November of last year. It’s a use-after-free (UAF) vulnerability that allows Android apps installed on a user’s smartphone to escalate their system privileges. This flaw can be exploited to trigger memory corruption as well as to execute arbitrary code with elevated privileges.

How to keep your Android phone secure

A hand holding a phone securely logging in

(Image credit: Google)

In order to keep your Android phone safe from attacks exploiting these and other vulnerabilities, it’s essential you install the latest updates as soon as they become available.

This can be done by heading to the Settings menu and scrolling down to About Phone. Tapping on this menu item will then allow you to check for software updates which you should install if they’re available.

At the same time, installing one of the best Android antivirus apps can protect you from malware or any malicious apps that leverage these vulnerabilities in their attacks. You also want to make sure that Google Play Protect is enabled on your device and you don’t have to download this Android antivirus app as it comes pre-installed.

We’ll likely hear more from Google about these vulnerabilities and how one of them was being used in attacks in the wild once enough Android users install the security updates that patch them.

More from Tom's Guide

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Latest in Android Phones
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
vivo x200 ultra camera array
Vivo’s next premium phone could have a camera unlike anything we’ve seen before — here’s how
Google Pixel 9a with thumbs up and thumbs down icons
Google Pixel 9a — 5 reasons to buy and 3 reasons to skip
Pixel 9 Pro XL held in the hand with price drop badge.
Not a typo! This epic deal makes the flagship Pixel 9 Pro XL the same price as the budget Pixel 9a
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights