Android’s September 2026 Updates Patch 180 Vulnerabilities
Google's September 2026 Android security updates patch 180 vulnerabilities including critical Wi-Fi memory corruption flaw CVE-2026-28662.
Google released September 2026 Android security updates addressing 180 vulnerabilities across two patch levels. The 2026-09-01 level fixes 95 bugs including 23 critical System component flaws enabling RCE, EoP, and DoS. The 2026-09-05 level addresses 85 additional defects in kernel and vendor components including a Wi-Fi memory corruption flaw (CVE-2026-28662) enabling remote code execution without privileges or user interaction.
- 180 total vulnerabilities patched across two September 2026 patch levels
- 23 critical System component flaws could enable RCE, EoP, and DoS
- CVE-2026-28662 is a Wi-Fi memory corruption allowing remote code execution
- First Android bulletin with fixes since two no-vulnerability months
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-28662 | Heap Buffer Overflow in Android Wi-Fi Direct (P2P) Provisioning Discovery Enables Nearby RCE CVE-2026-28662 is a heap buffer overflow causing an out-of-bounds write in p2p_process_prov_disc_bootstrap_req in p2p_pd.c, the code that handles Wi-Fi P2P (Wi-Fi Direct) provisioning discovery bootstrap requests in Android's Wi-Fi stack. It is triggered when a nearby attacker sends a crafted bootstrap request over the air while the device's Wi-Fi is enabled; no user interaction or privileges are required. Successful exploitation yields remote (proximal/adjacent) code execution, meaning anyone within Wi-Fi radio range could run code on the device. Android devices running software prior to the September 2026 Android Security Update are affected. Exploitation is not currently observed: there is no public proof-of-concept, it is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.1%. Do: Install the September 2026 Android Security Update (or your device vendor's equivalent build) as soon as it is available and verify the patch level in Settings > About phone. Until patched, consider disabling Wi-Fi Direct/peer-to-peer sharing and Wi-Fi when not needed, since exploitation requires proximity. The patch is part of the September 2026 release that fixes 180 vulnerabilities in total. | 8.0 | <1% |
| massorder of billions of Android devices worldwide carry the affected Wi-Fi Direct code, though exploitation requires an attacker within radio range |
Full article416 words · extracted from securityweek.com · click to collapse
After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates.
As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates).
“The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory.
The security refresh addresses 56 security defects in the System component, including 23 critical-severity flaws that could lead to remote code execution (RCE), elevation of privilege (EoP), and denial-of-service (DoS).
The update also fixes 37 vulnerabilities in the Framework component, including three critical-severity bugs, and one flaw in Android runtime.
The second part of the update, the 2026-09-05 security patch level, contains fixes for 85 security defects across Android’s kernel and its components, as well as TV, Arm, Imagination Technologies, MediaTek, Tsingteng Micro, Unisoc, and Qualcomm components.
Advertisement. Scroll to continue reading.
“Android’s September Bulletin is heavy in volume, containing a range of critical and high-severity patches. It’s worth noting that many of the critical severity updates are located in the System, which is responsible for most of a phone’s core functionality like app operation,” Jamf senior enterprise strategy manager Adam Boynton said.
“Most concerning from this list is CVE-2026-28662 because it’s a Wi-Fi-related memory corruption flaw. If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation. It’s crucial that organizations issue the updates across their device fleet as soon as possible,” Boynton added.
Devices updated to a security patch level of 2026-09-05 or newer contain patches for all these vulnerabilities, as well as for the flaws resolved with the previous Android patches.
There are no specific security patches for Wear OS, Android XR, and Android Automotive OS this month. Their updates, however, fix all the issues described in the September 2026 Android security bulletin.
Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Related: Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
Related: Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities
Related: Critical Remote Code Execution Vulnerability Patched in Android
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/