Google released the June 2026 Android security patches fixing 124 vulnerabilities including one zero-day under limited targeted exploitation in the Framework component. The updates also resolve 18 critical issues and arrive as Google scales back some bug bounties for AI-discoverable flaws.

Google is addressing an actively exploited zero-day in the Android Framework.
The company updated its Android and Chrome vulnerability rewards programs, offering bounties of up to $1.5 million for some Android exploits.
Security teams should prioritize the 2026-06-05 patch level on all managed Android 14 and later devices to block local privilege escalation.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
CISA warned that hackers are actively exploiting a recently patched high-severity flaw in SolarWinds Serv-U software to crash servers and added it to its Known Exploited Vulnerabilities Catalog. The agency ordered federal agencies to patch by June 19 and urged all organizations to mitigate the ongoing attacks immediately.
S&P Dow Jones Indices refused to waive seasoning, profitability, or public float rules for SpaceX's IPO, blocking accelerated S&P 500 entry that could have unlocked billions in passive funds. The same barriers now apply to expected IPOs from OpenAI and Anthropic, limiting exposure of retirement assets to unprofitable AI bets.
New York lawmakers approved a one-year moratorium on new large data centers, the first such statewide measure if signed by Governor Hochul. The pause aims to study environmental and energy impacts amid growing AI-driven demand.