Platform certificates used to sign Android system apps were compromised, allowing malware to be signed with legitimate certificates. The compromise was disclosed recently, but the exact timeline and details of the incident are unclear. Affected devices may be vulnerable to malware, particularly if they are no longer receiving updates. The impact of the compromise appears to be limited to specific brands and models of devices.