Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices.

The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should install the latest available update as soon as their device manufacturer releases it.

The most serious flaws affect the Android System component. Google said these critical vulnerabilities could lead to remote code execution, or RCE, without requiring additional execution privileges or user interaction.

In a successful attack, a threat actor may be able to run malicious code on a vulnerable device remotely, potentially before the user is aware of any compromise.

Android Security Update September 2026

The September update fixed several critical System RCE vulnerabilities, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. The flaws affect multiple Android releases, including Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17.

The bulletin also includes CVE-2026-52993, a critical remote code execution vulnerability in a kernel component associated with Transparent Inter-Process Communication.

Kernel-level vulnerabilities matter because the kernel manages core system functions and hardware access. Exploitation could give an attacker a powerful foothold inside the operating System.

Google also fixed critical elevation-of-privilege flaws in System and Framework components that could allow attackers with limited access to gain higher permissions.

Attackers may combine these issues with other vulnerabilities to escape app sandboxes, access protected data, turn off security controls, or take broader control of the device.

Critical Framework issues include CVE-2026-28666 and CVE-2026-55273, both of which could allow remote privilege escalation without user interaction.

Google also fixed CVE-2026-49932, a critical denial-of-service issue in Framework that could make an affected device or service unavailable. The 2026-09-05 patch level expands coverage to Android TV, the Linux kernel, chipset components, and vendor-specific drivers.

Component CVE Vulnerability Type Severity Affected Android Versions / Subcomponent
Framework CVE-2026-28666 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2, 17
Framework CVE-2026-55273 Elevation of privilege Critical Android 16, 16 QPR2, 17
Framework CVE-2026-49932 Denial of service Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-28604 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-28618 Remote code execution Critical Android 16, 16 QPR2, 17
System CVE-2026-28639 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-28662 Remote code execution Critical Android 16, 16 QPR2, 17
System CVE-2026-49882 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49884 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49919 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49921 Remote code execution Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-27280 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2
System CVE-2026-28590 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2
System CVE-2026-33636 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-45515 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-45531 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49879 Elevation of privilege Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49918 Elevation of privilege Critical Android 16 QPR2, 17
System CVE-2026-49927 Elevation of privilege Critical Android 16 QPR2, 17
System CVE-2026-55277 Elevation of privilege Critical Android 16 QPR2, 17
System CVE-2026-55285 Elevation of privilege Critical Android 16, 16 QPR2, 17
System CVE-2026-58820 Elevation of privilege Critical Android 16, 16 QPR2, 17
System CVE-2026-58823 Elevation of privilege Critical Android 17
System CVE-2026-28653 Denial of service Critical Android 14, 15, 16, 16 QPR2, 17
System CVE-2026-49926 Denial of service Critical Android 16 QPR2, 17
System CVE-2026-55256 Denial of service Critical Android 14, 15, 16, 16 QPR2, 17
Kernel CVE-2026-31629 Elevation of privilege Critical NFC
Kernel CVE-2026-58846 Elevation of privilege Critical Protected Kernel-Based Virtual Machine
Kernel CVE-2026-58848 Elevation of privilege Critical Protected Kernel-Based Virtual Machine
Kernel CVE-2026-58941 Elevation of privilege Critical Protected Kernel-Based Virtual Machine
Kernel Components CVE-2026-52993 Remote code execution Critical Transparent Inter-Process Communication
Qualcomm Closed-Source Components CVE-2026-25289 Not disclosed Critical Qualcomm closed-source component

Kernel fixes include critical elevation-of-privilege vulnerabilities in NFC and Protected Kernel-Based Virtual Machine components, tracked as CVE-2026-31629, CVE-2026-58846, CVE-2026-58848, and CVE-2026-58941.

The update further contains high-severity fixes affecting Arm Mali GPUs, Imagination Technologies PowerVR GPUs, MediaTek modem and multimedia components, Unisoc modem components, and Qualcomm software. One Qualcomm closed-source component vulnerability, CVE-2026-25289, is rated critical.

Google stated that Google Play Protect continues to monitor for potentially harmful applications and is enabled by default on devices that include Google Mobile Services. However, platform protections should not replace patching.

Users who install apps from third-party sources face additional risk and should be particularly careful to keep Android and Google Play System updates current.

To verify protection, open Settings, go to Security and privacy, and check the Android security update level. Devices running the 2026-09-05 patch level or later include all applicable fixes in the September bulletin.

Devices with the 2026-09-01 level receive the core Android framework, runtime, System, and Project Mainline fixes. At the same time, the later patch level also includes applicable kernel, TV, and vendor component updates.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks appeared first on Cyber Security News.