AI-assisted close-up of Pixel and Samsung phone cameras against a navy background.
Technology · News

September’s Android Security Update Fixes a Critical System Flaw: Check Your Patch Level

Google’s September 2026 Android Security Bulletin, published 8 September, fixes a critical remote code execution flaw in the System component across two patch levels, and Samsung’s matching release adds 31 of its own fixes. How to read your phone’s patch date.

Reference photo: SimonWaldherr / Wikimedia Commons, CC BY-SA 4.0, https://creativecommons.org/licenses/by-sa/4.0/. Generatively adapted; adaptation under the same licence. Not a demonstration of an installed update.
Michel ElijahPublished 12 September 2026 Checked 12 September 2026 3 min read

Google published the September 2026 Android Security Bulletin on 8 September, with an update on 10 September. The most serious fix is for a critical flaw in Android’s System component that Google says could allow remote code execution without any extra privileges. Samsung released its own September maintenance package on the same day. If your phone shows a security patch level older than 1 September 2026, it has not received these fixes yet.

The September bulletin has two patch levels, 2026-09-01 and 2026-09-05. A phone on 2026-09-05 or later has every fix in the bulletin; 2026-09-01 covers the core Android fixes. Google’s advice is to update to a build with the 2026-09-01 level or later.

Google does not report any of this month’s issues as being under limited, targeted exploitation. That lowers the urgency, but a remote code execution bug in a core component is still the kind of fix to install when it is offered.

What the Bulletin Fixes

Google’s summary describes the most severe issue as a critical security vulnerability in the System component that could lead to remote code execution with no additional execution privileges needed. For the 2026-09-01 level, the bulletin lists 36 Framework issues, 71 System issues, five Kernel issues, three in Android TV, and single issues in Android Runtime, Setup Wizard and kernel components. The 2026-09-05 level adds a long list of fixes in components supplied by chip makers, including Arm, Imagination and MediaTek.

Source: Android Open Source Project: Android Security Bulletin, September 2026, read 12 September 2026.

Two things the bulletin does not do: it does not name any vulnerability as exploited in the wild this month, and it does not tell you when your particular phone will get the update. That timing is set by the phone maker and, for phones bought on a plan, sometimes by the carrier.

Source: Android Open Source Project: Android Security Bulletin, September 2026, read 12 September 2026.

Samsung’s September Package

Samsung’s security page dates its September 2026 Security Maintenance Release to 8 September. Samsung says the package includes 18 critical and 41 high-severity patches from the Android bulletin, plus 31 Samsung-specific items. Two of the Samsung items it rates critical are heap-based buffer overflows in its image decoder library, one in the DNG decoder and one in the JPEG decoder, which Samsung says could allow remote or arbitrary code execution. In plain terms, a malformed image file is the sort of thing those fixes guard against.

Source: Samsung Mobile Security: Security Updates (SMR Sep-2026), read 12 September 2026.

How to Check Your Phone

Google’s bulletin says device owners can verify their security patch level in Android’s settings and should install available updates. The steps below are editorial and were not performed on a device for this article; menu names vary by manufacturer.

  1. Open Settings and look for the security or software update section, then find the line showing the Android security update or security patch level.

    You should see a date. On many phones it is under About phone; on Samsung phones it is under Software information.

  2. Compare that date with 1 September 2026 and 5 September 2026.

    A date of 2026-09-05 or later means every fix in this bulletin is installed; 2026-09-01 means the core fixes are.

  3. If the date is older, use the software update option to check for a new build, and install it on Wi-Fi with the battery charged.

    If nothing is offered, the manufacturer has not released the update for your model yet. Check again in a week rather than sideloading anything.

Source: Android Open Source Project: Android Security Bulletin, September 2026, read 12 September 2026.

Sources and How This Was Checked

The vulnerability descriptions, counts and advice come from Google’s Android Security Bulletin for September 2026 (published 8 September, updated 10 September) and Samsung’s security update page (SMR Sep-2026, dated 8 September), both read on 12 September 2026. No phone was updated or examined for this article, and the checking steps restate what those pages say without a hands-on test.

Related on Tech X Telco: Before you update to iOS 27: backup, storage and installation checklist.

Michel ElijahContent Advisor

Michel Elijah covers technology, streaming and online security for Tech X Telco. He writes practical how-to guides on everything from email troubleshooting to spotting the latest scams doing the rounds in Australia, with a focus on clear steps anyone can follow.

Spotted something wrong? Corrections are recorded in the open. Report a correction

Keep reading
All stories
Telco

Telstra’s July Outage Review: Network Timing Was Never Treated as Critical

Catch-up: Telstra published the findings of Technology Audit Partners’ external investigation on 2 September 2026. The July outage was triggered by incorrect date information after timing-system maintenance, and the review found Telstra had not treated network timing as a critical “sovereign function”. What Telstra says it has changed.

News

One useful thing a week.

One setting worth changing, one service or AI change that matters, and one practical guide. No spam, unsubscribe any time.

Free · Australian · Unsubscribe any timeWe email a confirmation link first. Your address is stored only to send this newsletter.