Skip to content
SoftwareSep 12, 20264 min read

Android September Update: What the Two Security Patch Dates Mean

September brings 180 Android security fixes. A September 5 patch level covers all applicable issues; September 1 guarantees a smaller set, not a complete inventory.

ByMobileTech Desk

Illustrative photo: an older Galaxy S21 software-update screen, not the September 2026 release. Image: Pexels.

Two quiet months in a row, Android's monthly bulletin shipped without a single new vulnerability disclosure. September made up the difference in one go: 180 fixes, spread across the operating system, the Linux kernel and components from six hardware vendors.

Most of the coverage will tell you to update. That advice is correct and almost useless on its own, because whether you can update, and what you actually get when you do, depends on details Android hides in plain sight.

September 5 certifies the full applicable set

The September bulletin has two patch levels. The 2026-09-01 level carries 95 fixes covering Android Runtime, Framework, System, the Setup Wizard and several Project Mainline components, some of which arrive through Google Play system updates rather than a full OS push. The 2026-09-05 level adds the other 85, and that is where the Linux kernel, Android TV and vendor hardware fixes live.

The distinction matters because the patch date specifies the minimum set of fixes a device must include. Google says a device showing 5 September 2026 or later must have all applicable fixes from both levels and previous bulletins. A 1 September date guarantees the earlier set. It does not certify the complete September 5 set, but it also does not prove that every kernel or vendor fix is absent. Some issues may already be fixed or may not affect that hardware.

Pixel owners can see this play out right now. Google pushed an out-of-cycle update to the Pixel 11 series that 9to5Google described as likely to be a hot patch for post-launch bugs rather than the expected Android 17 QPR1 release, and its security patch level is 1 September, not 5 September. Google also appears to have pulled the initial OTA partway through, then posted revised factory and OTA images. Users who installed the earlier update were receiving another download of about 97MB.

What the serious bugs actually are

Google flagged the worst issue as a critical flaw in the System component allowing remote code execution with no additional privileges and no action required from the user, without naming a single CVE as the standout. The shape of that description is the part to pay attention to. No user interaction is required in the described exploit conditions. Google assesses severity assuming platform mitigations are disabled or successfully bypassed; the description is not evidence of an attack against every phone.

System accounts for 56 of the September 1 fixes on its own, 23 of them critical. Framework accounts for 37, Android Runtime for one. TechRepublic singled out CVE-2026-28662 among the critical System entries because it sits in Android's Wi-Fi stack, alongside CVE-2026-28604, CVE-2026-28618 and CVE-2026-28639. Affected versions run from Android 14 through Android 17.

Samsung's month has a wrinkle worth knowing about

Samsung's parallel bulletin covers 90 vulnerabilities: 58 inherited from Google, of which 18 are critical and 40 high severity, one high-severity fix from Samsung Semiconductor affecting Exynos parts, and 31 Samsung-specific issues. Two of those deserve a mention because of where they sit. CVE-2026-21095 and CVE-2026-21096 are heap-based buffer overflows in Samsung's image codec library, hitting the DNG and JPG decoders.

Samsung says these decoder vulnerabilities can allow remote code execution, and its fixes add input validation or correct the implementation. The bulletin does not establish a particular messaging-app attack route, so a thumbnail or preview should not be presented as a demonstrated exploit.

The rollout itself started sideways. SammyGuru reported that rather than leading with flagships, Samsung folded the September patch into a One UI 9 beta build for the Galaxy A55, with the patch arriving as part of that beta rather than a standalone release. SammyGuru's running list has the update reaching the Galaxy A55, A57, Z Fold 8, Z Fold 8 Ultra and Z Flip 8 so far, with the usual staged expansion across regions over the following weeks. The Galaxy Z Fold 4 and Flip 4, meanwhile, have dropped from monthly to quarterly patches.

Check the security date and the support window

Check the date, not the Android version. Settings, then Security and privacy, then System and updates on most builds, though manufacturers move it. You are looking for a security patch date, and you want 5 September 2026 or later.

Check the manufacturer's notes if the date stays at 1 September. That level does not certify all applicable September 5 fixes. Install available updates, then check the device-specific bulletin instead of treating the date as a list of exactly which bugs remain.

Do not lean on Play Protect for this. It detects harmful apps. It cannot patch Android, the kernel, or a bug in your SoC vendor's driver, so it is not a substitute for the patches in this bulletin.

Work out where your phone sits in its support window. Devices past their support window may receive no further fixes, while quarterly-patch devices such as the Fold 4 do not have a monthly delivery commitment. If you are buying this month, the remaining update commitment is a specification, and it belongs on the comparison sheet next to the battery size.

Sources: techrepublic.com · secnews.gr · 9to5google.com · sammyguru.com · source.android.com · security.samsungmobile.com

More from the desk