Critical Microsoft UFO Flaw Exposes Android Devices to Remote Control
Microsoft’s open-source UFO framework uses AI agents to automate tasks across applications and devices, including interactions with Android hardware. Such tools can require broad access to systems and user interfaces, making authentication and connection controls a critical security boundary. A failure at that layer can expose more than stored information, allowing an attacker to operate a connected device and perform actions with the privileges available to the agent.
The newly disclosed vulnerability, tracked as CVE-2026-73296, carries a critical CVSS score of 9.4. It can allow an attacker to establish an unauthorized connection and remotely control an Android device, according to the advisory details. The flaw affects UFO version 3.0.7 and earlier releases. A fix is available in version 3.0.8, and users are advised to update promptly or restrict access to the framework’s communications ports until the upgrade can be completed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →