Google Patches 180 Android Vulnerabilities in September 2026 Update
Google's latest Android security update eliminates 180 flaws, including critical remote code execution bugs that require no user interaction. The fixes span two separate patch releases in early September.

A major security push from Google in September 2026 tackles 180 vulnerabilities embedded throughout Android, with some critical issues enabling attackers to run code from a distance without any user involvement. The remediation effort rolls out across two distinct security patch tiers.
On Sept. 1, Google released fixes for 95 flaws spanning Android Runtime, Framework, System, Setup Wizard and multiple Project Mainline modules. Five days later, the Sept. 5 patch level introduced 85 additional corrections targeting the Linux kernel, Android TV and components supplied by hardware and chipset manufacturers.
According to Google, the most dangerous vulnerability sits within the System component, permitting remote code execution without requiring elevated permissions or any user action. The company refrained from designating a single CVE identifier as the primary concern. Among the Sept. 1 corrections, 56 target the System component alone, with 23 carrying critical severity ratings. The Framework received 37 patches, while Android Runtime received one.
Some flaws could give attackers deep access
Google's September bulletin documents critical System vulnerabilities including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639 and CVE-2026-28662, among others. CVE-2026-28662 merits particular attention due to its impact on Android's Wi-Fi stack.
The patch set also resolves serious kernel-level issues, including vulnerabilities in NFC and Protected Kernel-Based Virtual Machine functionality. Fixes specific to individual vendors address hardware from Arm, MediaTek, Qualcomm, Unisoc and Imagination Technologies.
Google's September bulletin identifies affected versions spanning Android 14 through Android 17. The actual deployment of these fixes to any given phone hinges on its maker, specific model and how much longer the manufacturer intends to support it. Phones no longer covered by manufacturer support may continue facing these risks.
Samsung's parallel rollout
Alongside Google's efforts, Samsung unveiled its own September 2026 security bulletin covering both Google-sourced and Samsung-developed vulnerabilities affecting its Galaxy line. The bulletin encompasses 18 critical and 40 high-severity issues originating from Google, plus 31 fixes unique to Samsung. Two critical heap-based buffer overflows in Samsung's image codec library (CVE-2026-21095 and CVE-2026-21096) compromise the DNG and JPG decoders.
Samsung notes that patch availability depends on geographic location and device model, with premium devices receiving monthly updates while other models get patches every three months. The Galaxy Z Fold 4 and Flip 4 have transitioned to the quarterly schedule.
What users should do
Google urges Android users to maintain current software versions on their devices whenever feasible. Any device displaying the Sept. 5, 2026, security patch level or a later date incorporates all relevant corrections from both September patch releases.
To verify your device's patch status, navigate to Settings > Security and privacy > System and updates to locate the security patch date, though the exact menu path may differ depending on your phone's manufacturer. Should updates be waiting, apply them without delay.
IT teams overseeing multiple Android devices should audit their inventory to pinpoint machines that have exited the manufacturer support window. While Google Play Protect offers detection capabilities for certain malicious software, it cannot address vulnerabilities residing in Android itself, the Linux kernel or hardware-level components.


