1,398 iOS and Android vulnerabilities published this year
Phones are computers.Secure them like it.
Phishing, malicious apps and shadow AI hit phones every day, with a fraction of the protection laptops get. Securepoint shows you where the gaps are, what your regulations expect, and how to close them.
The problem
Phones carry the same data as laptops, and now most of the fraud. Here is the evidence.
Every phone channel rivals email.
Together, they dwarf it.
Fraud reported to the FTC, by how the scammer first made contact. Compare each channel to email, then stack them.
What arrives on each channel
Top scam types by channel, 2025. Hover or tap a row for losses.
One text, one call, one missed ring.
Real attacks that started on a phone and ended inside a company. Pick one and step through it, or press play.
Same data. Same threats.
Not the same protection.
What a typical company laptop has, next to what a typical company phone has. Tap any row to see why it matters.
Live threats
What is hitting phones right now, pulled from public feeds every day.
Mobile threat tracker Live data
Live data on everything aimed at phones, sorted by threat type. Pulled daily from the NVD, CISA, EPSS, FTC, FBI, APWG, OpenPhish, GitHub, MITRE and more.
The text scams that work
The scam types people reported most often by text in 2025, with yearly losses through June 2026. Hover or tap for details.
New phishing pages, week by week
Pages first seen in the OpenPhish community feed. Many arrive by text, but this covers phishing across the web. Hover or tap for detail.
The bigger picture
Phishing attacks per quarter across all channels, and what people lost
Unwanted texts and calls reported to regulators
Complaints filed each week. Texts go to the FCC and calls to the FTC, so the two charts use different scales. Hover or tap for detail.
Vulnerability trends
2026 by month
iOS and Android CVEs published to the NVD each month
Where they land
2026 so far, by component. Click one to filter the table.
Vulnerabilities to act on
Ranked by what attackers are actually doing: CISA’s exploited list first, then EPSS, the chance a flaw gets exploited in the next 30 days. Switch to Newest for the latest. Click a row for what to do.
| ID | Platform | Severity | What it means | Fixed in | Share |
|---|
Exploited in the wild
Phone flaws confirmed as used in real attacks this year, from three trackers. Hover or tap a badge for detail.
iPhone security updates this year
Each iOS release, how many flaws it fixed, and whether any were already being exploited.
Zero-days used against phones
Flaws attackers were already using before a fix existed, by the year they were patched.
App and browser flaws by month
Vulnerabilities in mobile apps and browsers published to the NVD in 2026
Most affected apps
Mobile apps with the most published flaws this year, not counting browsers
Browsers
Recent app flaws to act on
The latest high and critical flaws, one per app. Click an ID for the NVD record.
Flaws in the code inside apps
Libraries and SDKs that app developers build on. A flaw here reaches every app that ships it.
Chipset and firmware flaws by month
Qualcomm, MediaTek, Unisoc and Arm vulnerabilities published in 2026. These sit below the operating system.
Where they hit
Grouped by keywords in each description
By chipset maker
Recent chipset flaws to act on
Fixes ship through each phone maker’s monthly updates, so a current patch level is the only defense.
Security fixes each month, by phone maker
Flaws each maker patched, by the month they were published. Pixel and Samsung fixes come on top of Google’s Android bulletin.
Source: NVD. Counts follow NVD publication dates, which can trail a maker’s release by days or weeks, so busy months cluster around big updates.
Losing support in the next 12 months
Pixel and Galaxy models whose security updates end within a year. Plan replacements now.
Which versions still get security fixes
Status as tracked by endoflife.date
iOS
Android
Check a phone model
Pixel and Samsung Galaxy models. See when security updates stop.
How Wi-Fi networks are secured
Percent of Wi-Fi networks logged by WiGLE volunteers, by encryption type.
New Android malware samples each week
APK files submitted to MalwareBazaar
Most active malware families
Last 12 weeks
Stalkerware
Apps sold to secretly monitor another person’s phone.
These are indicators for checking phones, not a count of infections. A work phone carrying one of these apps is exposing everything on it.
Targeted spyware investigations
Indicators published from investigations into spyware aimed at specific people.
- Add the domains and IP addresses to the blocklist in your DNS filter or firewall.
- For people likely to be singled out, check their phone with the Mobile Verification Toolkit, a free forensic tool that looks for the apps and traces. It takes some technical skill.
- Indicators go out of date as attackers move servers, so a clean result does not prove a phone is safe.
This spyware is aimed at chosen people: journalists, activists, officials and executives. The index is kept by the open-source Mobile Verification Toolkit project and includes sets from Amnesty International’s Security Lab. Dates show when the research was published or the set joined the index.
AI tool flaws by month
Vulnerabilities in AI assistants, agents, MCP servers and model tooling published in 2026
Most affected AI tools
Hover for detail
Recent AI tool flaws to act on
The latest high and critical flaws, one per tool. Unapproved AI tools on phones and laptops inherit all of these.
Most of these tools reach phones as apps, browser sessions or connected agents. Pair this with the AI app use policy.
Real attacks on AI systems
Latest AI incidents
Where you stand
Check your own phones, then see what your regulations expect of them.
How protected are your phones in use?
Eight yes-or-no questions on phishing, risky apps, shadow AI and more. About two minutes. You get a score, your top gaps, and the playbooks that close them.
The regulatory hub
One guide per framework, ten in all: what the text requires, how it applies to phones in use, and the evidence an auditor will ask to see.
Stay ahead
The twice-weekly brief, ready-to-use playbooks, and plain-language reference.
The brief
Mobile security news twice a week, each story with one line on why it matters to the people running the devices.
Playbooks, policies and checklists
The playbooks, policies and training kits everyone rebuilds from scratch, written for how phones actually get attacked. Free with your email.
Reference
The terms, vendors and incidents you need to look up in the middle of a meeting.
Glossary
Plain definitions, no marketing
Vendor directory
Alphabetical and unranked. Securepoint doesn’t review vendors.
Go further
Get the free brief, tell us which paid tools you’d use, and meet who’s behind this.
Start free. Everything here is.
Every tool on this site costs nothing today. Paid tools come later, shaped by the people who use the free ones.
Five minutes, twice a week, no vendor pitches
- What changed on phones this weekNew exploited flaws, scams spreading by text, and which updates to push first
- Why it matters to youEvery story ends with one plain line on what to do about it
- The quarterly reportOriginal numbers from the tracker, before anyone else sees them
- Every template unlockedPolicies, playbooks and checklists, free to download
Free forever. Unsubscribe in one click. Your email is never sold or shared.
Free today, no account needed
01Live threat trackerPhishing, OS, app, chipset and AI flaws, updated daily 02Two-minute self-checkScore your phones and get your top gaps 03Framework guidesTen frameworks, from HIPAA and PCI DSS to the FTC Safeguards Rule, translated for phones 04ToolkitPlaybooks, policies and checklists 05ReferenceGlossary and a vendor-neutral directoryTools for teams and the MSPs who serve them
Pick everything you’d use and join the waitlist. Early members help decide what gets built first and get founding pricing.
About
Securepoint is written by someone who has spent over two decades in mobile and mobile security, mostly on the carrier side, working with the people who deploy it at scale.
Most security programs still treat phones as something to manage rather than something to protect. Nobody would call a laptop secure just because it can be wiped when lost. Securepoint exists to work out what protecting phones in use actually takes, framework by framework.
The author works in mobile security at Lookout. Views here are their own. Securepoint doesn’t review, rank or recommend vendors.
Send a tip
Spotted an incident we missed, a mapping that’s wrong, or a rule that changed? Corrections get credited in the next brief.