Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices.
The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should install the latest available update as soon as their device manufacturer releases it.
The most serious flaws affect the Android System component. Google said these critical vulnerabilities could lead to remote code execution, or RCE, without requiring additional execution privileges or user interaction.
In a successful attack, a threat actor may be able to run malicious code on a vulnerable device remotely, potentially before the user is aware of any compromise.
Android Security Update September 2026
The September update fixed several critical System RCE vulnerabilities, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. The flaws affect multiple Android releases, including Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17.
The bulletin also includes CVE-2026-52993, a critical remote code execution vulnerability in a kernel component associated with Transparent Inter-Process Communication.
Kernel-level vulnerabilities matter because the kernel manages core system functions and hardware access. Exploitation could give an attacker a powerful foothold inside the operating System.
Google also fixed critical elevation-of-privilege flaws in System and Framework components that could allow attackers with limited access to gain higher permissions.
Attackers may combine these issues with other vulnerabilities to escape app sandboxes, access protected data, turn off security controls, or take broader control of the device.
Critical Framework issues include CVE-2026-28666 and CVE-2026-55273, both of which could allow remote privilege escalation without user interaction.
Google also fixed CVE-2026-49932, a critical denial-of-service issue in Framework that could make an affected device or service unavailable. The 2026-09-05 patch level expands coverage to Android TV, the Linux kernel, chipset components, and vendor-specific drivers.
| Component | CVE | Vulnerability Type | Severity | Affected Android Versions / Subcomponent |
|---|---|---|---|---|
| Framework | CVE-2026-28666 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| Framework | CVE-2026-55273 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| Framework | CVE-2026-49932 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28604 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28618 | Remote code execution | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-28639 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28662 | Remote code execution | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-49882 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49884 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49919 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49921 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-27280 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2 |
| System | CVE-2026-28590 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2 |
| System | CVE-2026-33636 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-45515 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-45531 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49879 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49918 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-49927 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55277 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55285 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-58820 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-58823 | Elevation of privilege | Critical | Android 17 |
| System | CVE-2026-28653 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49926 | Denial of service | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55256 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| Kernel | CVE-2026-31629 | Elevation of privilege | Critical | NFC |
| Kernel | CVE-2026-58846 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel | CVE-2026-58848 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel | CVE-2026-58941 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel Components | CVE-2026-52993 | Remote code execution | Critical | Transparent Inter-Process Communication |
| Qualcomm Closed-Source Components | CVE-2026-25289 | Not disclosed | Critical | Qualcomm closed-source component |
Kernel fixes include critical elevation-of-privilege vulnerabilities in NFC and Protected Kernel-Based Virtual Machine components, tracked as CVE-2026-31629, CVE-2026-58846, CVE-2026-58848, and CVE-2026-58941.
The update further contains high-severity fixes affecting Arm Mali GPUs, Imagination Technologies PowerVR GPUs, MediaTek modem and multimedia components, Unisoc modem components, and Qualcomm software. One Qualcomm closed-source component vulnerability, CVE-2026-25289, is rated critical.
Google stated that Google Play Protect continues to monitor for potentially harmful applications and is enabled by default on devices that include Google Mobile Services. However, platform protections should not replace patching.
Users who install apps from third-party sources face additional risk and should be particularly careful to keep Android and Google Play System updates current.
To verify protection, open Settings, go to Security and privacy, and check the Android security update level. Devices running the 2026-09-05 patch level or later include all applicable fixes in the September bulletin.
Devices with the 2026-09-01 level receive the core Android framework, runtime, System, and Project Mainline fixes. At the same time, the later patch level also includes applicable kernel, TV, and vendor component updates.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks appeared first on Cyber Security News.
