Google issues Android security updates: who can get them and how
Google's October Android updates fix critical flaws, but many devices get patches late or never.
Google published October Android security updates for versions 14, 15, 16, 16-qpr2, and 17, including several Critical vulnerabilities that can be exploited without user interaction. No specific CVE identifiers are named, and exploitation in the wild is not reported. A large share of devices still run Android 12 or earlier, and vendor testing delays patches even on supported phones. Samsung, for example, places some Galaxy S22 and Galaxy A models on a quarterly rather than monthly schedule.
- October patches cover Android 14, 15, 16, 16-qpr2, and 17.
- Several Critical flaws can be exploited without user interaction.
- About four in ten devices were still on Android 12 or earlier.
- Samsung updates some Galaxy S22 and Galaxy A models quarterly.
Full article495 words · extracted from malwarebytes.com · click to collapse
Google has published security fixes for Android. The October updates are available for Android operating system versions 14, 15, 16, 16-qpr2, and 17 where “qpr” stands for Quarterly Platform Release. QPRs are interim updates Google pushes out between major yearly cycles.
These Android security bulletins contain valuable information for Android users. The updates are important as they fix several vulnerabilities rated as Critical, which can be exploited without users even doing anything.
However, we don’t write about them very often. The main reason for that lack of attention is that many Android users aren’t able to get the updates immediately and lots of others will never see them.
Google’s October fixes list Android 14 and newer, but a substantial share of the Android ecosystem still runs older software. In the distribution figures reported about last year, roughly four in ten devices were running Android 12 or earlier. This was while Android 13 still received updates which ended early March 2026.
And then there is the patch gap caused by device vendors meaning that even phones that remain supported may have to wait until the vendors test and sometimes modify the patches, so they work with their devices. And other vendors are on a different stride. For example, Samsung lists devices including the Galaxy S22 series and several Galaxy A models on a quarterly rather than a monthly security-update schedule.
You can imagine that cybercriminals love to get their hands on known vulnerabilities that many users have not yet been able to patch. Looking at the number of users that are unable to patch immediately that makes for an enormous target group.
How to stay safe
Get the updates as soon as they are made available to you is the most important word of advice here.
For most Android phones this is the general idea: open Settings, find Software update or System update (sometimes under System or About phone), check for updates, and follow the instructions to download, install, and restart. The menu names vary between vendors and even models, but the process is broadly the same.
If that doesn’t work for you or you can’t find instructions for your specific device, post what you’re looking for in the comments. We have lots of helpful readers.
Other things you can do:
- Use up-to-date real-time anti-malware protection.
- Refrain from sideloading unless it’s absolutely necessary.
- Make sure Google Play Protect is enabled. If you are a Malwarebytes Mobile Security user, you can check this using Trusted Advisor.
Should you decide to get a new Android phone, read our blog Upgrading your Android device? Read this first.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.