180 Android Security Flaws Patched: What Users Should Do

180 Android Security Flaws Patched: What Users Should Do

Android September update fixes 180 vulnerabilities Image: Generated via Google’s Nano Banana

Google’s September Android update fixes 180 security flaws, including critical bugs. Learn how to check your phone’s security patch level.

Sep 10, 2026

Google’s September 2026 Android security update addresses 180 vulnerabilities across the operating system, including critical flaws that could allow attackers to execute code remotely without user interaction.

The update is divided between two security patch levels. The Sept. 1 release fixes 95 vulnerabilities across Android Runtime, Framework, System, Setup Wizard and several Project Mainline components. The Sept. 5 level adds another 85 fixes covering the Linux kernel, Android TV and components from chip and hardware vendors.

Google said the most serious issue is a critical flaw in the System component that could enable remote code execution without requiring additional privileges or any action from the user. They did not single out one CVE as the most serious vulnerability. Of the Sept. 1 fixes, 56 affect the System component, including 23 critical-severity flaws. The Framework accounts for 37 fixes, while Android Runtime accounts for one.

Some flaws could give attackers deep access

The September bulletin includes critical System vulnerabilities such as CVE-2026-28604, CVE-2026-28618, CVE-2026-28639 and CVE-2026-28662, among others. CVE-2026-28662 stands out because it affects Android’s Wi-Fi stack.

The update also addresses serious kernel vulnerabilities, including flaws affecting NFC and Protected Kernel-Based Virtual Machine components. Vendor-specific fixes cover Arm, MediaTek, Qualcomm, Unisoc and Imagination Technologies hardware.

Google’s September bulletin lists affected versions from Android 14 through Android 17. Whether an individual phone receives the fixes depends on its manufacturer, model and remaining support period. Devices that have reached the end of manufacturer support may remain exposed.

More Google coverage

Advertisement

Samsung’s parallel rollout

Samsung has released its own September 2026 security bulletin addressing Google and Samsung-specific vulnerabilities affecting Galaxy devices. These include 18 critical and 40 high-severity issues from Google, along with 31 Samsung-specific fixes. Two critical heap-based buffer overflows in Samsung’s image codec library (CVE-2026-21095 and CVE-2026-21096) affect the DNG and JPG decoders.

The company notes that availability varies by region and model, with flagship devices receiving monthly patches while others get quarterly updates. The Galaxy Z Fold 4 and Flip 4 have dropped to quarterly status.

What users should do

Google recommends keeping Android devices updated wherever possible. A device showing the Sept. 5, 2026, security patch level or later includes all applicable fixes from both September patch levels.

Users should check their phone’s security patch date under Settings > Security and privacy > System and updates, although the path may vary by manufacturer. If there are available patches, users should update their systems promptly.

Organizations managing Android fleets should also identify devices that have reached the end of manufacturer support. Google Play Protect can detect some harmful applications, but it cannot patch vulnerabilities in Android, the Linux kernel or hardware components.

Read more: Learn how Android security updates work, how to check your patch level and when an unsupported phone may need replacing.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.