Android October 2026 security bulletin (5 Oct): 25 CVEs, 7 Critical — System privilege escalation needing no user interaction, several in the Bluetooth stack; one patch level, 2026-10-01
Google published the Android Security Bulletin for October 2026 on 5 October 2026. It lists 25 vulnerabilities, all fixed at a single security patch level, 2026-10-01: 7 rated Critical and 18 High. Google says the most severe is a Critical flaw in the System component that could lead to local escalation of privilege with no additional execution privileges and no user interaction. The Critical System entries are CVE-2026-55269, CVE-2026-55280, CVE-2026-58835 and CVE-2026-58880 (privilege escalation, Android 16, 16 QPR2 and 17) plus CVE-2026-49933 and CVE-2026-55265 (denial of service); the CVE records published on 6 October place CVE-2026-58880, CVE-2026-58835 and CVE-2026-55269 in Bluetooth stack code (a race condition, a heap buffer overflow and an input-validation flaw). The Framework section's Critical entry, CVE-2026-58865, is a remote denial of service needing no privileges or user interaction. The High-rated set includes CVE-2026-49878, a System remote code execution bug in the Wi-Fi module, and five Framework privilege escalations. Wi-Fi (CVE-2026-45524, CVE-2026-49878) and Telephony (CVE-2026-58859) fixes also ship as Google Play system updates. The bulletin does not flag any of these as exploited, and Google says AOSP source patches follow within 48 hours. Chipset fixes from MediaTek's own October bulletin (desk card mediatek-october-2026-bulletin-20261005) arrive separately through device makers. The Pixel bulletin for October was not yet published when this card was checked. Primary: Android Security Bulletin, October 2026.
- Product
- Android (AOSP Framework and System components; Wi-Fi and Telephony Mainline modules) on OEM phones and tablets
- Versions
- Critical: CVE-2026-55269, CVE-2026-55280, CVE-2026-58835, CVE-2026-58880 (EoP; Android 16, 16 QPR2, 17), CVE-2026-49933 (DoS; 16, 16 QPR2, 17), CVE-2026-55265 (DoS; 14 to 17), CVE-2026-58865 (Framework remote DoS; 14 to 17). High: 18 more, including CVE-2026-49878 (Wi-Fi RCE). Fixed at security patch level 2026-10-01 or later.
- CVSS
- Critical (Android severity rating; the bulletin gives no CVSS scores)
- Exploited in Australia?
- unknown
- Patch to
- Move Android phones and tablets to security patch level 2026-10-01 or later as each maker ships it, and make sure Google Play system updates are current for the Wi-Fi and Telephony fixes. Use your MDM to find handsets stuck on older patch levels, and plan to retire devices that no longer receive monthly updates.
Primary: Android Security Bulletin — October 2026 (published 5 Oct 2026) · Vendor: Android Open Source Project — October 2026 bulletin, patch level 2026-10-01 · CVE: CVE-2026-55269, CVE-2026-55280, CVE-2026-58835, CVE-2026-58880, CVE-2026-49933, CVE-2026-55265, CVE-2026-58865, CVE-2026-49878, CVE-2026-45524, CVE-2026-58859 · CVE-2026-58880 record — Bluetooth btif_rc.cc race condition (published 6 Oct 2026)
