Google’s September bulletin includes critical Android flaws, while a reported CERT-In warning covers Android 14 through Android 17. Here’s the patch level to check.
Key points
In this article
Google’s September Android bulletin lists critical flaws. Learn what patch levels 2026-09-01 and 2026-09-05 mean and where to check your phone.
Google updated its September 2026 Android Security Bulletin on September 15, adding issue details and links to patches in the Android Open Source Project. The bulletin includes critical vulnerabilities, including a System flaw that Google says could allow remote code execution without additional execution privileges or user interaction. A reported warning from India’s Computer Emergency Response Team, CERT-In, covers Android 14 through Android 17, including Android 16 QPR2.
The practical question is simple: open your phone’s software-update or security-update settings and check the Android security update date. A device showing 2026-09-01 has the fixes assigned to that patch level. A device showing 2026-09-05 or later includes all applicable fixes in Google’s September bulletin.
Google published the September 2026 Android Security Bulletin on September 8 and updated it on September 15. The update added further issue details and links to corresponding AOSP changes.
CERT-In reportedly issued its Android warning on September 14. The warning covered Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17, and urged users to install the latest security update supplied for their phones.
The warning describes security risks associated with the vulnerabilities; it is not a report that every phone running one of those Android versions has been compromised. Whether a particular device receives a fix depends on its model, manufacturer software build, region, carrier, and installed patch level.
Google’s bulletin lists affected version ranges for Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17. The version number alone is not the protection status: an Android 14 phone can receive a newer security patch without moving to a newer Android release.
The vulnerabilities span core Android and vendor-related components. Google lists issues involving the Android Runtime, Framework, System, Setup Wizard, TV, Kernel, Arm, Imagination Technologies, MediaTek, Unisoc, Qualcomm, and Qualcomm closed-source components. Google also names Google Play system update components including Media Framework, Documents UI, Media Codecs, MediaProvider, Telephonycore, UWB, Wi-Fi, and adbd.
The later patch level includes additional kernel, vendor, Qualcomm, and TV issues. That is why the date shown in Settings matters more than the Android version label by itself.
The bulletin classifies the reported flaws as remote code execution, elevation of privilege, information disclosure, and denial of service. These categories describe different potential outcomes:
Google identifies critical RCE issues in the System component, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. The bulletin also lists critical elevation-of-privilege and denial-of-service issues in System and Framework.
The 2026-09-05 section adds critical kernel issues involving NFC and Protected Kernel-Based Virtual Machine, along with CVE-2026-52993, a critical RCE issue in Transparent Inter-Process Communication.
The two September dates represent different coverage levels:
A later patch date does not mean every phone has the same software build or the same component set. Google’s bulletin applies fixes according to the components present on a device, while manufacturers determine when and how those fixes reach individual models.
Google says Google Play Protect is enabled by default on devices with Google Mobile Services and can warn about potentially harmful applications. It is an additional protection layer, not a replacement for the applicable security patch.
A phone running Android 14, 15, 16, 16 QPR2, or 17 therefore needs a closer look at its security patch date. The Android release number identifies the platform version; the patch date identifies the security-update level installed on that device.
Other Languages
Read this article in another available language.
NeoTeo
Steam’s reported September 2026 free-games weekend includes six premium titles, with four temporary trials and two games…
Anthropic is reportedly weighing an unnamed AI model as GPT-6 Astra gains enterprise ground, putting safety, spending an…
Apple plans to use 14 iPhone 18 Pro units at Dodger Stadium for Giants–Dodgers MLB coverage, with compact camera positio…
Copyright © 2005-2026 NeoTeo. All rights reserved.
Follow NeoTeo on Google to see more of our stories
AI Search


