Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Android’s October 2026 Updates Patch 25 Vulnerabilities

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Android vulnerability

Google this week announced the rollout of fresh Android security updates that resolve 25 vulnerabilities in the Framework and System components.

The fresh release arrives on devices as the 2026-10-01 security patch level and marks a change from the updates released over the past several years, which have been split into two parts.

Android’s October 2026 patches resolve seven flaws in Framework and 18 in System, including a total of seven critical-severity bugs (one in Framework and six in System).

“The most severe of these issues is a critical security vulnerability in the System component that could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation,” Google notes in its advisory.

Of the issues resolved in Framework, two can lead to denial-of-service (DoS) and five to elevation of privilege (EoP). In System, Google resolved eight EoP vulnerabilities, five DoS bugs, one remote code execution (RCE) flaw, and four information disclosure issues.

The advisory also mentions three security defects addressed via Google Play system updates, including one in Telephonycore and two in WiFi.

Advertisement. Scroll to continue reading.

In addition to the Android patches, Pixel devices received fixes for six vulnerabilities that could lead to EoP and information disclosure, including three critical-severity issues affecting the Bluetooth, GDMC, and GSA components.

The Android Automotive OS update contains fixes for all the bugs resolved with the Android October 2026 updates and for five other high-severity bugs leading to EoP.

Google makes no mention of any of these vulnerabilities being exploited in the wild. However, users are advised to update their devices as soon as possible.

Related: Android’s September 2026 Updates Patch 180 Vulnerabilities

Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Related: FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

Related: Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.