Cyber Security News

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices.

The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should install the latest available update as soon as their device manufacturer releases it.

The most serious flaws affect the Android System component. Google said these critical vulnerabilities could lead to remote code execution, or RCE, without requiring additional execution privileges or user interaction.

In a successful attack, a threat actor may be able to run malicious code on a vulnerable device remotely, potentially before the user is aware of any compromise.

Android Security Update September 2026

The September update fixed several critical System RCE vulnerabilities, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. The flaws affect multiple Android releases, including Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17.

The bulletin also includes CVE-2026-52993, a critical remote code execution vulnerability in a kernel component associated with Transparent Inter-Process Communication.

Kernel-level vulnerabilities matter because the kernel manages core system functions and hardware access. Exploitation could give an attacker a powerful foothold inside the operating System.

Google also fixed critical elevation-of-privilege flaws in System and Framework components that could allow attackers with limited access to gain higher permissions.

Attackers may combine these issues with other vulnerabilities to escape app sandboxes, access protected data, turn off security controls, or take broader control of the device.

Critical Framework issues include CVE-2026-28666 and CVE-2026-55273, both of which could allow remote privilege escalation without user interaction.

Google also fixed CVE-2026-49932, a critical denial-of-service issue in Framework that could make an affected device or service unavailable. The 2026-09-05 patch level expands coverage to Android TV, the Linux kernel, chipset components, and vendor-specific drivers.

ComponentCVEVulnerability TypeSeverityAffected Android Versions / Subcomponent
FrameworkCVE-2026-28666Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2, 17
FrameworkCVE-2026-55273Elevation of privilegeCriticalAndroid 16, 16 QPR2, 17
FrameworkCVE-2026-49932Denial of serviceCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-28604Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-28618Remote code executionCriticalAndroid 16, 16 QPR2, 17
SystemCVE-2026-28639Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-28662Remote code executionCriticalAndroid 16, 16 QPR2, 17
SystemCVE-2026-49882Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49884Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49919Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49921Remote code executionCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-27280Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2
SystemCVE-2026-28590Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2
SystemCVE-2026-33636Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-45515Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-45531Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49879Elevation of privilegeCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49918Elevation of privilegeCriticalAndroid 16 QPR2, 17
SystemCVE-2026-49927Elevation of privilegeCriticalAndroid 16 QPR2, 17
SystemCVE-2026-55277Elevation of privilegeCriticalAndroid 16 QPR2, 17
SystemCVE-2026-55285Elevation of privilegeCriticalAndroid 16, 16 QPR2, 17
SystemCVE-2026-58820Elevation of privilegeCriticalAndroid 16, 16 QPR2, 17
SystemCVE-2026-58823Elevation of privilegeCriticalAndroid 17
SystemCVE-2026-28653Denial of serviceCriticalAndroid 14, 15, 16, 16 QPR2, 17
SystemCVE-2026-49926Denial of serviceCriticalAndroid 16 QPR2, 17
SystemCVE-2026-55256Denial of serviceCriticalAndroid 14, 15, 16, 16 QPR2, 17
KernelCVE-2026-31629Elevation of privilegeCriticalNFC
KernelCVE-2026-58846Elevation of privilegeCriticalProtected Kernel-Based Virtual Machine
KernelCVE-2026-58848Elevation of privilegeCriticalProtected Kernel-Based Virtual Machine
KernelCVE-2026-58941Elevation of privilegeCriticalProtected Kernel-Based Virtual Machine
Kernel ComponentsCVE-2026-52993Remote code executionCriticalTransparent Inter-Process Communication
Qualcomm Closed-Source ComponentsCVE-2026-25289Not disclosedCriticalQualcomm closed-source component

Kernel fixes include critical elevation-of-privilege vulnerabilities in NFC and Protected Kernel-Based Virtual Machine components, tracked as CVE-2026-31629, CVE-2026-58846, CVE-2026-58848, and CVE-2026-58941.

The update further contains high-severity fixes affecting Arm Mali GPUs, Imagination Technologies PowerVR GPUs, MediaTek modem and multimedia components, Unisoc modem components, and Qualcomm software. One Qualcomm closed-source component vulnerability, CVE-2026-25289, is rated critical.

Google stated that Google Play Protect continues to monitor for potentially harmful applications and is enabled by default on devices that include Google Mobile Services. However, platform protections should not replace patching.

Users who install apps from third-party sources face additional risk and should be particularly careful to keep Android and Google Play System updates current.

To verify protection, open Settings, go to Security and privacy, and check the Android security update level. Devices running the 2026-09-05 patch level or later include all applicable fixes in the September bulletin.

Devices with the 2026-09-01 level receive the core Android framework, runtime, System, and Project Mainline fixes. At the same time, the later patch level also includes applicable kernel, TV, and vendor component updates.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago