securityonline.info 9 Sept 2026, 08:36 UTC

Google Fixes Critical Android Flaws Enabling Remote Code Execution

Google Fixes Critical Android Flaws Enabling Remote Code Execution

GOOGLE’S September 2026 Android security bulletin fixes a set of critical flaws across System, Framework and Kernel components, addressing remote code execution and privilege escalation risks. The bulletin confirms five CVEs in total, with one highest‑severity item rated CVSSv3 9.8: CVE-2026-52993.

Other entries include CVE-2026-25289 (Stack-based buffer overflow in WLAN firmware, CVSS not provided as exploited), CVE-2026-31629 (CWE-667, multiple fixed components), CVE-2026-28604 (System, awaiting analysis), and CVE-2026-28666 (Framework, awaiting analysis). At the time of the report, there were no confirmed reports of active exploitation. Google notes that devices at patch level 2026‑09‑05 or later are protected against all identified weaknesses.

The vulnerabilities affect multiple major Android releases (14, 15, 16, 16‑QPR2, and 17) and several hardware‑specific components from manufacturers such as Qualcomm, Arm, MediaTek and Imagination Technologies. Exploitation pathways described in the bulletin involve sending crafted network traffic or malformed data to trigger unsafe memory processing or bypass permission checks, potentially enabling unauthorised remote code execution or privilege escalation without user interaction.

Practically, the guidance is to apply the latest security updates immediately through over‑the‑air updates or Google Play system updates, and to verify device patch levels. Google has indicated that corresponding source patches will be released to the Android Open Source Project within 48 hours. No active in‑the‑wild exploitation has been confirmed to date.

View full article

Article by CyberSIXT