Sanctioned Russian Firm Uncovers 11 Vulnerabilities in Google and Apple Products
Russian cybersecurity firm Positive Technologies, currently under U.S. sanctions, has identified 11 security vulnerabilities in Google and Apple products. The flaws include critical risks to macOS and Android devices, enabling unauthorized access and control via methods like malicious NFC tags. Both companies have released patches, but unupdated devices remain exposed.
Editor, Lazyfounder

Russian cybersecurity firm Positive Technologies, currently under U.S. sanctions, has identified 11 security vulnerabilities in Google and Apple products. The flaws include critical risks to macOS and Android devices, enabling unauthorized access and control via methods like malicious NFC tags. Both companies have released patches, but unupdated devices remain exposed.
30 SEC SUMMARY
- Russian cybersecurity firm Positive Technologies, under U.S. sanctions, identified 11 security vulnerabilities in Google and Apple products.
- Nine flaws impacted Apple devices, including macOS, enabling unauthorized system control and data corruption.
- Two high-severity Android vulnerabilities allowed NFC-based attacks and unauthorized network changes.
- Both Google and Apple released patches, but details about affected versions remain unclear.
- Devices without the latest updates remain at risk from these exploits.
TABLE OF CONTENTS
- Findings from a Sanctioned Firm
- Apple Device Flaws
- Android Vulnerabilities
- Patches and Remaining Risks
- Background
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Positive Technologies, a Russian cybersecurity firm under U.S. sanctions, identified 11 security flaws in Google and Apple products.
- Nine vulnerabilities affected Apple devices, including macOS, with risks ranging from unauthorized system control to data corruption.
- Two high-severity Android flaws allowed attackers to exploit NFC tags or alter network settings without user approval.
- Google patched the Android vulnerabilities in September 2026; Apple released fixes but did not specify affected versions.
- Devices without the latest updates remain exposed to these security risks.
Findings from a Sanctioned Firm
A Russian cybersecurity firm, Positive Technologies, has reported discovering 11 security vulnerabilities in products developed by Google and Apple. The firm, which is currently under U.S. sanctions, identified flaws that could allow attackers to compromise devices through malicious NFC tags or unauthorized app actions, according to TechRadar.
Apple Device Flaws
The vulnerabilities include nine flaws affecting Apple’s macOS and other devices. Among these, one flaw permitted a malicious app to gain the highest level of control over a computer, while another exposed protected system information. A separate vulnerability in the operating system’s kernel could lead to device failure or data corruption.
Android Vulnerabilities
Two high-severity vulnerabilities were found in Android, including Pixel phones. The first flaw allowed attackers to use a crafted NFC tag to install and run an application without the user’s consent. The second enabled an app to alter network settings, such as joining a Wi-Fi network or adjusting proxy parameters, without requiring additional permissions or user confirmation.
Patches and Remaining Risks
Google addressed the Android vulnerabilities in its September 2026 patches. Apple also released fixes for the reported flaws but did not disclose which operating system versions were affected. Neither company has acknowledged the report from Positive Technologies, though the patches suggest the vulnerabilities are legitimate.
Devices that have not installed the latest updates remain at risk from these exploits.
Background
Positive Technologies is a Russian cybersecurity firm specializing in vulnerability research and security testing. The company has been under U.S. sanctions, which restricts its ability to engage with American entities or access certain technologies.
NFC (Near Field Communication) is a short-range wireless technology used for data exchange between devices, commonly employed in contactless payments, access control, and automated interactions with tags or posters.
Apple and Google routinely release security updates to address vulnerabilities in their operating systems, though they often do not provide detailed public commentary on individual reports.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
This report highlights a paradox in cybersecurity: even firms under sanctions can play a critical role in identifying vulnerabilities that affect global tech giants. For founders and operators, this underscores two key realities. First, the security landscape remains fragmented—no single entity, regardless of its geopolitical standing, has a monopoly on uncovering threats. Second, patch management is non-negotiable. Companies that delay updates expose themselves to risks that could have been mitigated with basic hygiene.
The lack of transparency from Apple and Google about affected versions is concerning. It forces users to assume their devices are vulnerable until proven otherwise, which is a poor security posture. For startups, this is a reminder to prioritize clarity in security communications—customers and partners need actionable information, not ambiguity.
Key takeaways
- Positive Technologies, a sanctioned Russian firm, discovered 11 vulnerabilities in Google and Apple products.
- Nine flaws affected Apple devices, with risks including unauthorized system control and data corruption.
- Two Android vulnerabilities enabled NFC-based attacks and unauthorized network changes without user consent.
- Google patched the Android flaws in September 2026, while Apple released fixes without specifying affected versions.
- Unpatched devices remain vulnerable to these exploits, emphasizing the importance of timely updates.
FAQ
What vulnerabilities did Positive Technologies discover?
The firm found 11 vulnerabilities across Google and Apple products. Nine affected Apple devices, including macOS, enabling unauthorized system control and data corruption. Two high-severity Android flaws allowed NFC-based attacks and unauthorized changes to network settings.
Have Google and Apple fixed these vulnerabilities?
Yes, Google patched the Android flaws in September 2026. Apple released fixes but did not specify which operating system versions were affected. Devices without the latest updates remain vulnerable.
Why is Positive Technologies under U.S. sanctions?
Positive Technologies, a Russian cybersecurity firm, has been sanctioned by the U.S. government, which restricts its ability to engage with American entities or access certain technologies. The sanctions are part of broader geopolitical measures.
How can users protect their devices from these vulnerabilities?
Users should install the latest security updates for their devices immediately. For Android, this includes the September 2026 patches. Apple users should ensure their devices are running the most recent version of macOS or iOS to mitigate risks.
Related on Lazyfounder
Sources
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


