After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates.
As usual, the updates are split into two parts. The first part arrives on devices as the 2026-09-01 security patch level and resolves 95 bugs across Android runtime, Framework, System, Setup Wizard, and multiple Project Mainline components (patched via Google Play system updates).
“The most severe of these issues is a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory.
The security refresh addresses 56 security defects in the System component, including 23 critical-severity flaws that could lead to remote code execution (RCE), elevation of privilege (EoP), and denial-of-service (DoS).
The update also fixes 37 vulnerabilities in the Framework component, including three critical-severity bugs, and one flaw in Android runtime.












