Samsung Galaxy owners have another security update to check for, and this one is about more than just new features.
Samsung released details of its October 2026 security update on Oct. 6, patching nine critical Android vulnerabilities, along with dozens of high- and moderate-severity flaws. The update also addresses Samsung-specific vulnerabilities, including several that could allow attackers with local access to execute arbitrary code.
The security release arrives as Samsung is expanding One UI 9 and Android 17 across its Galaxy lineup, making the latest update particularly relevant for owners navigating both major operating system upgrades and monthly security patches.
Samsung patches nine critical Android vulnerabilities
Samsung’s October 2026 Security Maintenance Release incorporates fixes from Google’s latest Android Security Bulletin, along with Samsung’s own patches.
Samsung lists nine Android CVEs as critical in its October package, with another 33 rated high and three rated moderate.
Several of the most serious vulnerabilities affect Android’s System component. Google said the most severe System vulnerability could allow a local attacker to escalate privileges without requiring additional execution privileges or any user interaction.
The critical System vulnerabilities include CVE-2026-55269, CVE-2026-55280, CVE-2026-58835, and CVE-2026-58880. These affect Android 16, Android 16 QPR2, and Android 17, according to Google’s October Android Security Bulletin.
Another critical vulnerability, CVE-2026-58865, affects the Android Framework and could cause a remote denial-of-service attack without requiring user interaction.
Google has not indicated in its bulletin that any of the October vulnerabilities are being actively exploited.
Galaxy-specific flaws could allow arbitrary code execution
The Android vulnerabilities are only part of Samsung’s October security package.
Samsung also disclosed 27 Samsung Vulnerabilities and Exposures, though it is withholding details on some for security reasons.
Several disclosed high-severity vulnerabilities could allow local attackers to execute arbitrary code:
- CVE-2026-21114, for example, is an out-of-bounds write vulnerability affecting a Samsung media library on Android 14 through Android 17. Samsung said a local attacker could exploit the flaw to execute arbitrary code.
- CVE-2026-21120 is a use-after-free vulnerability in Samsung’s WSM service that could potentially allow a local attacker to execute arbitrary code with system privileges. Another flaw, CVE-2026-21122, affects Samsung’s text-to-speech library and could also allow arbitrary code execution.
Samsung additionally patched vulnerabilities in HEIF image-processing components that could potentially lead to arbitrary code execution.
The company’s October package also includes four high-severity fixes from Samsung Semiconductor.
TechRepublic previously reported on Samsung’s August security update, which patched 56 vulnerabilities, demonstrating how Android security releases can combine vulnerabilities in Google’s operating system with flaws specific to Samsung hardware and software.
Samsung Internet gets a separate security fix
Samsung disclosed another notable vulnerability outside the main monthly firmware package.
A high-severity vulnerability tracked as CVE-2026-21132 affects Samsung Internet versions prior to 30.0.5.24. Samsung said improper input validation could allow a remote attacker to inject arbitrary script, although user interaction is required to trigger the vulnerability.
The vulnerability is fixed in Samsung Internet version 30.0.5.24.
Because Samsung Internet can be updated separately from the phone’s operating system through the app store, Galaxy users should make sure the browser itself is up to date, in addition to checking their device’s system security patch.
What Galaxy owners should do now
Galaxy owners should install applicable security updates as soon as they become available for their devices. Samsung schedules supported devices for monthly, quarterly, or biannual security updates, and the timing of individual releases can vary by model, region, and carrier.
Here are three things Galaxy users should do:
- Check for the October update: Open Settings > Software update, then select the available option to check for or download an update. The wording can differ depending on the device and software version.
- Update Samsung Internet: Make sure the browser is running version 30.0.5.24 or later, which fixes the high-severity CVE-2026-21132 vulnerability.
- Verify the security patch level: Don’t assume a recent One UI upgrade includes every current security fix. Check the device’s security software information to confirm its installed patch level.
Keeping a supported device current matters because Android vulnerabilities can accumulate on phones that no longer receive regular patches. TechRepublic previously examined which Galaxy phones may miss out on Android 17 and One UI 9, an increasingly important consideration as security support becomes a larger part of a smartphone’s usable lifespan.
For organizations managing Galaxy phones, the October release is also a reminder to verify security patch levels across managed devices rather than assuming a recent One UI update means every applicable security fix has been installed.
Also read: Samsung Ends Galaxy Z Fold 3 and Flip 3 Updates: Is It Time to Upgrade? to see what happens when Galaxy devices reach the end of guaranteed security support.