September 2026 Android Update Patches Critical RCE Flaws
Key Takeaways Google has released a critical Android security update for September 2026. Multiple severe vulnerabilities, including Remote Code Execution (RCE) flaws, affect various Android versions....
Key Takeaways
- Google has released a critical Android security update for September 2026.
- Multiple severe vulnerabilities, including Remote Code Execution (RCE) flaws, affect various Android versions.
- The vulnerabilities impact core Android System, Framework, and Kernel components, as well as vendor-specific drivers.
- Users are urged to install the latest security patches as soon as they become available from their device manufacturers to prevent potential remote attacks and privilege escalation.
Android Security Bulletin Addresses Critical RCE Flaws
Google has issued its September 2026 Android Security Bulletin, detailing fixes for numerous critical vulnerabilities that could enable remote code execution (RCE) on affected devices. This essential update, released on September 8th, incorporates security patch levels dated 2026-09-01 and 2026-09-05.
Table Of Content
Device owners are strongly advised to install these patches immediately upon their release by manufacturers to mitigate significant security risks.
Remote Code Execution in Android System Components
The most severe vulnerabilities are found within the core Android System component. According to Google, these critical flaws could permit attackers to execute arbitrary code remotely without requiring any elevated privileges or user interaction. This means a malicious actor could potentially compromise a vulnerable device and run harmful code before the user even becomes aware of an attack.
Several critical RCE vulnerabilities in the System component have been addressed, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. These issues impact a broad range of Android versions, specifically Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17.
Kernel-Level Vulnerabilities and Privilege Escalation
The September bulletin also highlights CVE-2026-52993, a critical RCE vulnerability located in a kernel component related to Transparent Inter-Process Communication. Kernel-level vulnerabilities are particularly concerning as the kernel is responsible for managing the operating system’s core functions and hardware access. Successful exploitation of such a flaw could grant an attacker a deep and powerful foothold within the device’s operating system.
Beyond RCE, Google has also patched critical elevation-of-privilege (EoP) vulnerabilities in both System and Framework components. These flaws could allow an attacker with limited access to escalate their permissions to a higher level. Attackers frequently chain these types of vulnerabilities together with others to bypass sandbox protections, access sensitive data, disable security features, or gain complete control over a device.
Notable critical Framework EoP issues include CVE-2026-28666 and CVE-2026-55273, both of which could enable remote privilege escalation without any user interaction. Additionally, CVE-2026-49932, a critical denial-of-service (DoS) vulnerability in the Framework, has been resolved, which could render an affected device or service unavailable.
The 2026-09-05 patch level extends its coverage to include fixes for Android TV, the Linux kernel, various chipset components, and vendor-specific drivers.
Comprehensive Fixes Across Components
The bulletin details a wide array of critical fixes:
| Component | CVE | Vulnerability Type | Severity | Affected Android Versions / Subcomponent |
|---|---|---|---|---|
| Framework | CVE-2026-28666 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| Framework | CVE-2026-55273 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| Framework | CVE-2026-49932 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28604 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28618 | Remote code execution | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-28639 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-28662 | Remote code execution | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-49882 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49884 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49919 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49921 | Remote code execution | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-27280 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2 |
| System | CVE-2026-28590 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2 |
| System | CVE-2026-33636 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-45515 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-45531 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49879 | Elevation of privilege | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49918 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-49927 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55277 | Elevation of privilege | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55285 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-58820 | Elevation of privilege | Critical | Android 16, 16 QPR2, 17 |
| System | CVE-2026-58823 | Elevation of privilege | Critical | Android 17 |
| System | CVE-2026-28653 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| System | CVE-2026-49926 | Denial of service | Critical | Android 16 QPR2, 17 |
| System | CVE-2026-55256 | Denial of service | Critical | Android 14, 15, 16, 16 QPR2, 17 |
| Kernel | CVE-2026-31629 | Elevation of privilege | Critical | NFC |
| Kernel | CVE-2026-58846 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel | CVE-2026-58848 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel | CVE-2026-58941 | Elevation of privilege | Critical | Protected Kernel-Based Virtual Machine |
| Kernel Components | CVE-2026-52993 | Remote code execution | Critical | Transparent Inter-Process Communication |
| Qualcomm Closed-Source Components | CVE-2026-25289 | Not disclosed | Critical | Qualcomm closed-source component |
Kernel fixes include critical EoP vulnerabilities in NFC and Protected Kernel-Based Virtual Machine components, identified as CVE-2026-31629, CVE-2026-58846, CVE-2026-58848, and CVE-2026-58941.
The update further contains high-severity fixes impacting various vendor components, including Arm Mali GPUs, Imagination Technologies PowerVR GPUs, MediaTek modem and multimedia components, Unisoc modem components, and Qualcomm software. Notably, one Qualcomm closed-source component vulnerability, CVE-2026-25289, is also rated as critical.
While Google Play Protect actively monitors for potentially harmful applications and is enabled by default on devices with Google Mobile Services, Google emphasizes that these platform protections are not a substitute for installing critical security patches. Users who install applications from third-party sources face increased risk and must prioritize keeping their Android and Google Play System updates current.
What You Should Do
- Install Updates Immediately: Check for and install the latest Android security update as soon as it is made available by your device manufacturer.
- Verify Patch Level: Navigate to Settings > Security and privacy on your device to confirm your Android security update level. Devices running the 2026-09-05 patch level or later include all applicable fixes from this bulletin. Devices with the 2026-09-01 level receive core Android framework, runtime, System, and Project Mainline fixes, while the later patch level also includes kernel, TV, and vendor component updates.
- Exercise Caution with Third-Party Apps: Be especially vigilant if you install apps from sources other than the official Google Play Store, as these can introduce additional risks.
- Maintain Google Play System Updates: Ensure your Google Play System updates are also current, as they contribute to overall device security.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.