ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Published September 10, 2026

A flaw in Android's built-in browser lets fake websites trick users into entering passwords and credit card info. Attackers can create convincing fake sites that steal real data when you log in or pay.

Report priority
Medium
Targets
Android

How it works

  • Fake websites use a trick to bypass Android's normal security checks.
  • When you visit a fake site, the browser lets it ask for your password or credit card details without warning.
  • Once you enter them, the fake site sends your info to the attacker's real server instead of the real company's site.
  • This happens because the browser does not properly check if a site is really who it claims to be before letting it ask for sensitive data.

What to do

Watch for updates from Google about a patch. In the meantime, avoid clicking on links from unknown sources, check website URLs carefully, and use a trusted password manager to monitor for data leaks. If you suspect your data was stolen, contact your bank or the affected service immediately.

Technical details

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results.

An exposed system stays exposed. A package looks useful right up until it isn’t.