Advisory
Published 2026-09-09
Verified 2026-09-19

Android September 2026 security bulletin: 180 vulns; Wi-Fi RCE CVE-2026-28662 called out

SecurityWeek (9 September 2026) covers Google's September 2026 Android Security Bulletin: 180 vulnerabilities patched. Jamf commentary highlighted CVE-2026-28662 as a Wi-Fi-related memory-corruption flaw that could enable remote code execution without additional privileges or user interaction if left unpatched. Devices on security patch level 2026-09-05 or newer include the full set. Wear OS, Android XR, and Android Automotive OS have no separate bulletin items this month but inherit the described fixes. Prefer the official Android Security Bulletin for CVE lists and severity. Primary: SecurityWeek; vendor bulletin preferred when linking builds.

Product
Android (AOSP / OEM builds)
Versions
Security patch level 2026-09-05 or newer
Exploited in Australia?
unknown
Patch to
OEM/Google security patch level 2026-09-05 or later; prioritise Wi-Fi stack fixes including CVE-2026-28662

Primary: Android Security Bulletin — September 2026 · Vendor: Android Open Source Project (bulletin) · CVE: CVE-2026-28662 · SecurityWeek (9 Sep 2026)

vulnerabilities