Headlines

180 Android Security Flaws Patched: What to Do


Google’s September 2026 Android security update addresses 180 vulnerabilities across the operating system, including critical flaws that could allow attackers to execute code remotely without user interaction.

The update is divided between two security patch levels. The Sept. 1 release fixes 95 vulnerabilities across Android Runtime, Framework, System, Setup Wizard and several Project Mainline components. The Sept. 5 level adds another 85 fixes covering the Linux kernel, Android TV and components from chip and hardware vendors.

Google said the most serious issue is a critical flaw in the System component that could enable remote code execution without requiring additional privileges or any action from the user. They did not single out one CVE as the most serious vulnerability. Of the Sept. 1 fixes, 56 affect the System component, including 23 critical-severity flaws. The Framework accounts for 37 fixes, while Android Runtime accounts for one.

Some flaws could give attackers deep access

The September bulletin includes critical System vulnerabilities such as CVE-2026-28604, CVE-2026-28618, CVE-2026-28639 and CVE-2026-28662, among others. CVE-2026-28662 stands out because it affects Android’s Wi-Fi stack.

The update also addresses serious kernel vulnerabilities, including flaws affecting NFC and Protected Kernel-Based Virtual Machine components. Vendor-specific fixes cover Arm, MediaTek, Qualcomm, Unisoc and Imagination Technologies hardware.

Google’s September bulletin lists affected versions from Android 14 through Android 17. Whether an individual phone receives the fixes depends on its manufacturer, model and remaining support period. Devices that have reached the end of manufacturer support may remain exposed.

More Google coverage

Samsung’s parallel rollout

Samsung has released its own September 2026 security bulletin addressing Google and Samsung-specific vulnerabilities affecting Galaxy devices. These include 18 critical and 40 high-severity issues from Google, along with 31 Samsung-specific fixes. Two critical heap-based buffer overflows in Samsung’s image codec library (CVE-2026-21095 and CVE-2026-21096) affect the DNG and JPG decoders.

The company notes that availability varies by region and model, with flagship devices receiving monthly patches while others get quarterly updates. The Galaxy Z Fold 4 and Flip 4 have dropped to quarterly status.

What users should do

Google recommends keeping Android devices updated wherever possible. A device showing the Sept. 5, 2026, security patch level or later includes all applicable fixes from both September patch levels.

Users should check their phone’s security patch date under Settings > Security and privacy > System and updates, although the path may vary by manufacturer. If there are available patches, users should update their systems promptly.

Organizations managing Android fleets should also identify devices that have reached the end of manufacturer support. Google Play Protect can detect some harmful applications, but it cannot patch vulnerabilities in Android, the Linux kernel or hardware components.

Read more: Learn how Android security updates work, how to check your patch level and when an unsupported phone may need replacing.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *