Google Android Family: September 2026 Regular Security Update Advisory
Sep 08 2026
Google has released security updates to address vulnerabilities in the Android product family.
The affected products include Android Qualcomm components, Android Qualcomm closed-source components, Android kernel components, Android Unisoc components, Android MediaTek components, Android Runtime, Android Framework, and Android System.
In the Android Framework, a “Critical” local privilege escalation vulnerability, a “Critical” denial-of-service vulnerability, a “High” remote code execution vulnerability, a “High” local privilege escalation vulnerability, a “High” information disclosure vulnerability, and a “High” denial-of-service vulnerability have been fixed.
In the Android System, a critical-rated remote code execution vulnerability, a critical-rated local privilege escalation vulnerability, a critical-rated denial-of-service vulnerability, a high-rated remote code execution vulnerability, a high-rated local privilege escalation vulnerability, a high-rated information disclosure vulnerability, and a high-rated denial-of-service vulnerability were fixed.
In Android Runtime, a high-severity local privilege escalation vulnerability was fixed.
In the Android Kernel (Transparent Inter-Process Communication, a kernel component for inter-process communication) component, a critical-severity vulnerability was fixed.
A high-severity vulnerability was fixed in the Android Unisoc (Modem, communication modem functionality) component.
A high-severity vulnerability in the Android MediaTek (Modem, HEVC decoder, apusys, trusted_mem, display, geniezone, vdec) component has been fixed.
High-severity vulnerabilities were also fixed in the Android Qualcomm (Security) component and the Android Qualcomm closed-source (Closed-source component) component.
The disclosed information states that product-specific patches were provided via an update on September 5, 2026.