Android users have a new security update to install.
Google’s September 2026 security release addresses multiple critical vulnerabilities across Android’s System, Framework, Kernel, and other components. Some of the most serious issues could allow attackers to run code remotely or gain higher privileges on an affected device.
The update was published on September 8, 2026, with security patch levels of September 1 and September 5. The exact update available depends on the device and manufacturer.
Remote Code Execution Is the Biggest Concern
Several critical vulnerabilities affect the Android System component.
These include:
CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921.
The main concern is remote code execution. Under the conditions described by Google, exploitation could allow malicious code to run without requiring additional execution privileges or interaction from the device owner.
That makes these vulnerabilities particularly important for both individual users and organizations managing Android devices.
A Kernel-Level RCE Was Also Patched
Another critical issue, CVE-2026-52993, affects a kernel component connected to Transparent Inter-Process Communication.
The Android kernel sits at the heart of the operating system and handles important interactions between software and hardware. A vulnerability at this level can therefore have significant security implications if successfully exploited.
Privilege Escalation Adds Another Layer of Risk
The September release is not limited to remote code execution.
Google also addressed multiple critical privilege-escalation vulnerabilities in Android System and Framework components.
These weaknesses could potentially allow an attacker who already has limited access to obtain greater permissions.
In a larger attack, privilege escalation can become especially dangerous when combined with another vulnerability. It could potentially help an attacker access protected information, bypass application restrictions, or gain greater control over the device.
Two critical Framework vulnerabilities, CVE-2026-28666 and CVE-2026-55273, are specifically associated with remote privilege escalation and do not require user interaction.
Other Critical Fixes
Google also addressed CVE-2026-49932, a critical denial-of-service vulnerability affecting Framework.
An exploited device or service could potentially become unavailable.
The September 5 security level also extends the fixes to additional areas, including Android TV, kernel components, chipset-related software, and vendor-specific drivers.
Affected Android Releases
The critical System vulnerabilities covered in the bulletin affect different combinations of:
- Android 14
- Android 15
- Android 16
- Android 16 QPR2
- Android 17
The bulletin also lists vulnerabilities affecting Kernel, Framework, Qualcomm, and other platform components.
Vendor Components Are Included Too
The security work extends beyond the Android core.
Google lists fixes involving components from Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm.
One Qualcomm closed-source component issue, CVE-2026-25289, is classified as critical.
This is important because Android security depends on more than the operating system itself. Device manufacturers and chipset vendors also play a role in delivering complete protection.