Overview
- Google published its September 2026 Android Security Bulletin documenting up to 180 fixed vulnerabilities that affect Android 14 through 17, with the company splitting fixes across two patch levels released in early September.
- Many of the corrected bugs are rated critical or high and include remote code execution (RCE) and elevation of privilege flaws that can let an attacker run code or gain higher rights on a device without user interaction.
- Google can patch some components directly through Google Play System updates (Project Mainline) but most patches require device makers to issue firmware updates, which creates staggered rollouts that vary by model and region.
- Samsung has published its own September bulletin and begun staged rollouts for Galaxy phones, adding two Galaxy‑specific critical image‑decoder RCEs (CVE‑2026‑21095 and CVE‑2026‑21096) and noting that availability will differ by device and carrier.
- Google says it has no evidence of active exploitation at publication, but reporting differences between roughly 90 and 180 fixes reflect Google’s split patch levels and vendor additions and underline why users should check for and install updates as they become available.