Google’s September 2026 Android Security Bulletin fixes more than 90 vulnerabilities affecting Android 14, 15, 16, 16 QPR2, and 17. The release rates 26 flaws as critical and 68 as high severity, including Android System remote-code-execution vulnerabilities that can be triggered without user interaction or additional execution privileges, depending on the affected CVE. It also addresses critical elevation-of-privilege and denial-of-service issues in the Framework and System, a critical Transparent Inter-Process Communication kernel-component RCE flaw, and defects in kernel, Android TV, and vendor components.
Google is distributing patch levels 2026-09-01 and 2026-09-05; devices at the latter level receive all applicable September fixes, including relevant kernel and vendor patches. Pixel and Samsung Galaxy devices are among the first receiving updates, while availability for other manufacturers may lag. Qualcomm separately released fixes for 14 high-severity vulnerabilities in software used by its mobile, wireless-connectivity, automotive, and computing platforms, which could expose confidential information or disrupt affected services. No active exploitation was reported at publication, but organizations should prioritize deployment of available Android and vendor updates.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Qualcomm Technologies released security updates addressing 14 high-severity vulnerabilities in software components used by its platforms and chipsets. Affected deployments include mobile devices, wireless-connectivity systems, automotive platforms, and computing solutions; exploitation could expose confidential information or affect service availability.
Google published its September 2026 Android Security Bulletin, providing patch levels 2026-09-01 and 2026-09-05. The bulletin remediated more than 90 flaws across Android Framework, System, kernel, and vendor components, including critical vulnerabilities that could enable remote code execution without user interaction.
Google and Samsung began rolling out the September patches to initial Pixel and Galaxy devices. Other device vendors may distribute the updates later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceacn.gov.it
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.