Microsoft Flaw Exposes Android Devices to Remote Hacking
A critical vulnerability in Microsoft's UFO automation framework has been discovered, allowing hackers to remotely control Android devices without authentication or user interaction.
The flaw, tracked as CVE-2026-73296, has a CVSS severity score of 9.4 out of 10 and affects versions of UFO before 3.0.8 when Mobile Model Context Protocol (MCP) services are configured for remote access.
Microsoft has released an updated version of the framework to address the issue, adding mandatory bearer token authentication to the Mobile MCP servers.