Google has confirmed that a critical Android vulnerability, CVE-2026-0073, could enable remote code execution without any user interaction required.