September 2026 Android Security Update Fixes Critical RCE Flaws
Google's September 2026 Android Security Bulletin addresses critical vulnerabilities, including multiple RCE flaws affecting Android versions up to Android 17.

Google has released its September 2026 Android Security Bulletin, detailing a series of critical vulnerabilities that could allow attackers to execute arbitrary code on affected devices without user interaction or elevated privileges. The security patch levels released are dated September 1, 2026, and September 5, 2026, with users strongly advised to install the latest available updates as soon as they are provided by their device manufacturers.
The most severe of these vulnerabilities reside within the Android System component. Google has identified several critical flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. These vulnerabilities impact a wide range of Android versions, spanning from Android 14 through to Android 17, including Android 16 QPR2.
Further compounding the risk, the bulletin also lists CVE-2026-52993, a critical remote code execution vulnerability found in a kernel component related to Transparent Inter-Process Communication (TIPC). Exploiting kernel-level vulnerabilities is particularly concerning as the kernel holds significant control over core system functions and hardware access, potentially granting an attacker a deep foothold within the operating system.
Beyond remote code execution, the September update also rectifies critical elevation-of-privilege vulnerabilities within the System and Framework components. These flaws could enable attackers with limited initial access to escalate their permissions, potentially allowing them to bypass security sandboxes, access sensitive data, disable security controls, or gain broader command over the device. Specific critical framework issues include CVE-2026-28666 and CVE-2026-55273, both of which facilitate remote privilege escalation without requiring user interaction.
Additionally, a critical denial-of-service (DoS) vulnerability, CVE-2026-49932, has been patched in the Framework component. This flaw could render an affected device or service inoperable. The patch level dated September 5, 2026, extends coverage to Android TV, the Linux kernel, various chipset components, and vendor-specific drivers, addressing further critical elevation-of-privilege vulnerabilities in NFC and Protected Kernel-Based Virtual Machine components (CVE-2026-31629, CVE-2026-58846, CVE-2026-58848, and CVE-2026-58941).
The update also includes fixes for high-severity vulnerabilities affecting components from Arm Mali GPUs, Imagination Technologies PowerVR GPUs, MediaTek, Unisoc, and Qualcomm. Notably, a critical vulnerability in a Qualcomm closed-source component, CVE-2026-25289, is also addressed.
While Google Play Protect offers continuous monitoring for malicious applications on devices with Google Mobile Services, Google emphasizes that these platform protections are not a substitute for timely patching. Users who obtain applications from third-party sources are at heightened risk and must ensure their Android and Google Play System updates are kept current. Users can check their security status by navigating to Settings > Security and privacy and reviewing the Android security update level.
This comprehensive update underscores the ongoing efforts by Google to secure the Android ecosystem against a wide array of sophisticated threats, from remote code execution to privilege escalation and denial-of-service attacks, across a broad spectrum of device versions and underlying hardware components.
Google's September 2026 Android security bulletin addresses a total of 180 vulnerabilities, expanding on the initial reporting of critical RCE flaws. The update covers a broad range of issues across Android's Framework, System, and Kernel components, aiming to bolster overall device security for users.