Google published security updates addressing dozens of flaws across the operating system on September 1, 2026. Specifically, Google patched several critical Android security vulnerabilities affecting the System, Framework, and Kernel components. These flaws allow unauthenticated attackers to execute arbitrary code or gain elevated privileges remotely. Devices running patch level 2026-09-05 or later resolve all identified flaws.
- Total: 5 CVEs
- Severity: 2 Critical · 1 High · 2 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-52993
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-52993 | 9.8 | CWE-415 | a438975a6dcdbd70865978c021650d1485586f0b, 4ee4deadaae7cb2e3d53af0fc889cf92a73413c0, d3556656c6daebf8def751c7e71d11dd0a180d24 (+13) | Not exploited |
| CVE-2026-25289 | 9.6 | Stack-based Buffer Overflow in WLAN Firmware | — | Not exploited |
| CVE-2026-31629 | 8.8 | CWE-667 | b2a23529593d011fb433a3d711fc597ed6a6bd2f, 665315df9c3486cb213fc44d83cc8bcd47fe0d26, 9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6 (+15) | Not exploited |
| CVE-2026-28604 | Awaiting analysis | Awaiting analysis | — | Not exploited |
| CVE-2026-28666 | Awaiting analysis | Awaiting analysis | — | Not exploited |
Why These Android Flaws Matter
Industry analysts estimate that Android powers more than 3 billion active devices globally. Consequently, critical Android security vulnerabilities present severe risks to both individual users and enterprise fleets. Attackers who exploit these bugs can access private data without user awareness. Furthermore, rogue applications can seize administrative access across affected smartphones and tablets. System compromise on this scale exposes confidential messages, personal media, and corporate credentials.
How the Attacks Work
Multiple flaws reside within core platform components. In the official advisory, Google warned that the most serious flaw threatens the core System. Specifically, the bulletin notes, “The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed.” Additionally, Google confirmed that “User interaction is not needed for exploitation.”
Attackers exploit CVE-2026-28604 in the System component by transmitting crafted network packets. This flaw triggers unsafe memory processing without user authorization. Meanwhile, CVE-2026-52993 targets the Transparent Inter-Process Communication protocol in the kernel. Threat actors exploit this flaw by sending malformed networking traffic directly to the device. In the Framework layer, CVE-2026-28666 allows attackers to bypass permission checks and escalate privileges. Detailed technical listings appear in the September 2026 Android Security Bulletin.
Affected Versions
These Android security vulnerabilities affect multiple major releases of the platform. Specifically, the bulletin covers Android versions 14, 15, 16, 16-qpr2, and 17. Additionally, several hardware-specific flaws impact components from Qualcomm, Arm, MediaTek, and Imagination Technologies. Currently, Google has confirmed no active in-the-wild exploitation. Furthermore, researchers report no public proof-of-concept code.
Patch and Mitigation Steps
Device manufacturers are distributing security updates over the air. Users should verify their device patch level under system settings. Devices with a security patch level of 2026-09-05 or later address all reported weaknesses. Moreover, Google will release corresponding source patches to the Android Open Source Project repository within 48 hours. Many components also receive automated fixes through Google Play system updates. Users should install pending updates immediately to keep their hardware protected.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!