
Critical Microsoft UFO MCP Flaw Lets Unauthenticated Attackers Remotely Control Android Devices
A critical vulnerability in Microsoft’s UFO agentic automation framework exposes Android devices to a complete, unauthenticated remote takeover. Tracked as CVE-2026-73296 with a CVSS score of 9.4, the flaw affects UFO versions up to and including v3.0.7, with no patched version currently available. The vulnerability resides in the Mobile MCP (Model Context Protocol) implementation at […]
The post Critical Microsoft UFO MCP Flaw Lets Unauthenticated Attackers Remotely Control Android Devices appeared first on Cyber Security News.