Google updated its September 2026 Android Security Bulletin on September 15, adding issue details and links to patches in the Android Open Source Project. The bulletin includes critical vulnerabilities, including a System flaw that Google says could allow remote code execution without additional execution privileges or user interaction. A reported warning from India’s Computer Emergency Response Team, CERT-In, covers Android 14 through Android 17, including Android 16 QPR2.

The practical question is simple: open your phone’s software-update or security-update settings and check the Android security update date. A device showing 2026-09-01 has the fixes assigned to that patch level. A device showing 2026-09-05 or later includes all applicable fixes in Google’s September bulletin.

What happened on September 14 and 15

Google published the September 2026 Android Security Bulletin on September 8 and updated it on September 15. The update added further issue details and links to corresponding AOSP changes.

CERT-In reportedly issued its Android warning on September 14. The warning covered Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17, and urged users to install the latest security update supplied for their phones.

The warning describes security risks associated with the vulnerabilities; it is not a report that every phone running one of those Android versions has been compromised. Whether a particular device receives a fix depends on its model, manufacturer software build, region, carrier, and installed patch level.

Which Android versions and components are involved

Google’s bulletin lists affected version ranges for Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17. The version number alone is not the protection status: an Android 14 phone can receive a newer security patch without moving to a newer Android release.

The vulnerabilities span core Android and vendor-related components. Google lists issues involving the Android Runtime, Framework, System, Setup Wizard, TV, Kernel, Arm, Imagination Technologies, MediaTek, Unisoc, Qualcomm, and Qualcomm closed-source components. Google also names Google Play system update components including Media Framework, Documents UI, Media Codecs, MediaProvider, Telephonycore, UWB, Wi-Fi, and adbd.

The later patch level includes additional kernel, vendor, Qualcomm, and TV issues. That is why the date shown in Settings matters more than the Android version label by itself.

What the vulnerabilities could allow

The bulletin classifies the reported flaws as remote code execution, elevation of privilege, information disclosure, and denial of service. These categories describe different potential outcomes:

  • Remote code execution (RCE): an attacker may be able to run code on the affected system.
  • Elevation of privilege (EoP): code may gain permissions beyond those normally available to it.
  • Information disclosure: data may become accessible to an unauthorized party.
  • Denial of service (DoS): a component may stop working or become unavailable.

Google identifies critical RCE issues in the System component, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919, and CVE-2026-49921. The bulletin also lists critical elevation-of-privilege and denial-of-service issues in System and Framework.

The 2026-09-05 section adds critical kernel issues involving NFC and Protected Kernel-Based Virtual Machine, along with CVE-2026-52993, a critical RCE issue in Transparent Inter-Process Communication.

How to read the September security patch levels

The two September dates represent different coverage levels:

Security patch levelWhat Google says it coversWhat to do with that information
2026-09-01Issues assigned to the first September patch level, along with earlier bulletin fixes required for the deviceThis is the minimum September date for the fixes assigned to that level
2026-09-05 or laterAll applicable fixes in the September bulletin, including the later kernel, vendor, Qualcomm, and TV issuesThis date represents broader September coverage when it is available for the device

A later patch date does not mean every phone has the same software build or the same component set. Google’s bulletin applies fixes according to the components present on a device, while manufacturers determine when and how those fixes reach individual models.

How to check and update an Android phone

  1. Open Settings.
  2. Go to the software-update or security-update section. The menu name varies by manufacturer.
  3. Check the displayed Android security update date.
  4. Install the latest update offered for the phone.
  5. Recheck the security patch date after the installation finishes.

Google says Google Play Protect is enabled by default on devices with Google Mobile Services and can warn about potentially harmful applications. It is an additional protection layer, not a replacement for the applicable security patch.

A phone running Android 14, 15, 16, 16 QPR2, or 17 therefore needs a closer look at its security patch date. The Android release number identifies the platform version; the patch date identifies the security-update level installed on that device.