Android September Security Update: Which Phones Need Patching Now?

Android’s September 2026 security update patches critical vulnerabilities across supported devices.

Android’s September 2026 security update patches critical vulnerabilities across supported devices. Image: Generated via Google’s Nano Banana

Google’s September Android security update fixes critical flaws. See which Pixel, Samsung, and other Android phones need patching now.

Written By
Ken Underhill
Ken Underhill
Sep 17, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Your Android phone may look fully updated and still be missing September's most important security fixes.

Google's September Android security release patches dozens of vulnerabilities across Android's Framework, System, kernel, runtime, and other components, including critical flaws that could enable remote code execution. Devices reporting the Sept. 5, 2026 security patch level or later must include all applicable fixes covered by Google's September Android bulletin.

But Android updates do not reach every phone at the same time. Google, Samsung, and other manufacturers distribute their own updates, making the security patch date on your device more important than simply knowing which version of Android it runs.

September Android update fixes critical security flaws

Google published its September 2026 Android Security Bulletin on Sept. 8. The bulletin page was updated Sept. 10, and Google's version history lists a Sept. 15 revision that updated the issue list and added AOSP links.

The release contains fixes split between the Sept. 1 and Sept. 5 security patch levels.

Among the most serious are multiple critical remote code execution vulnerabilities affecting Android's System component. Google says the most severe vulnerability in that section could lead to remote code execution without additional execution privileges or user interaction.

The affected components span Android itself and lower-level software, including the Android Runtime, Framework, System, kernel and kernel components, Google Play system components, and vendor hardware components.

Google says devices with the 2026-09-05 security patch level or newer must include all applicable fixes from both September patch levels, as well as those from previous Android security bulletins.

The update continues a busy year for Android security. Earlier this year, Google patched an Android zero-day under active exploitation, while another Android vulnerability could have allowed a nearby attacker to achieve zero-click remote shell access.

Advertisement

Which Android phones need the September patch?

The short answer is simple: supported Android devices that have not reached the Sept. 5 security patch level should be checked for an available manufacturer update.

That does not mean every Android phone will receive the same package on the same day.

Google publishes the Android security fixes, but device manufacturers are responsible for integrating applicable patches and distributing updates to their hardware. Manufacturers may also include additional fixes for vulnerabilities specific to their devices.

That creates several groups Android users should watch.

Google Pixel phones: Google published its September Pixel Update Bulletin on Sept. 15. Google says all supported Pixel devices will receive the 2026-09-05 security patch level, which addresses the Pixel-specific issues in the September bulletin as well as all applicable fixes in the broader September Android Security Bulletin.

Google says supported Pixel devices begin receiving OTA updates when the monthly bulletin is released, but it can take about one-and-a-half calendar weeks for the update to reach every supported device.

Samsung Galaxy phones: Samsung is distributing its September Security Maintenance Release for applicable Galaxy devices. The package combines Google's Android fixes with Samsung-specific patches.

Samsung's September release includes Google Android patches, a Samsung Semiconductor patch, and 31 Samsung Vulnerabilities and Exposures items. Among the Samsung-specific fixes are two critical heap-based buffer overflows in DNG and JPEG image decoders that could allow remote attackers to execute arbitrary code. Samsung notes that security-patch delivery can vary by region and model.

Other Android manufacturers: Motorola, Xiaomi, OnePlus, and other Android manufacturers follow their own security-update schedules. A vulnerability appearing in Google's bulletin does not necessarily affect every device, and manufacturers may package applicable Android fixes with their own device-specific patches.

For those phones, users should check the manufacturer's update information and, more importantly, the device's current security patch level.

Advertisement

Why the security patch level matters more than the Android version

Running Android 17 does not by itself mean a phone contains September's security fixes.

Google's September tables include vulnerabilities with fixes for Android 14, Android 15, Android 16, Android 16 QPR2, and Android 17. Which versions are affected varies by vulnerability.

The date shown under Android security update indicates the security patch level the manufacturer says is installed. A device reporting Sept. 1, 2026 must include the fixes assigned to the first September patch level. A device reporting on or after Sept. 5, 2026, must include all applicable patches associated with both September patch levels.

Google uses two security patch levels so Android partners can fix vulnerabilities common across devices more quickly while still encouraging manufacturers to bundle all applicable monthly fixes into a single update.

But operating-system flaws are only part of the attack surface. Android devices can also be targeted through vulnerabilities in hardware components, vendor software, and other device-specific code. 

Recent campaigns have used malware rather than OS exploits to compromise phones. The Manic Android malware, for example, can steal banking credentials and relay stolen information through nearby infected devices.

How to check whether your Android phone needs an update

Android users can check both their operating system update and security patch status in the device's Settings app. The exact menu names can vary by manufacturer and Android version.

On many Android devices, users can find the information under:

Settings → About phone → Android version

Look for the Android security update entry and its date.

If the device shows a security patch level older than Sept. 5, 2026, check for an available system update from the manufacturer.

Pixel owners can also check for updates under:

Settings → System → Software updates

Samsung Galaxy owners can generally use:

Settings → Software update → Download and install

Users should also check for system updates in Google Play, since Android devices can receive updates for some system components separately through Google Play.

Advertisement

What Android users and security teams should do now

For individual users, the most useful number in this story is not the Android version printed on the box. It is the date next to the Android security update.

If a device reports a security patch level of Sept. 5, 2026 or newer, its manufacturer is declaring that it includes all applicable fixes required by Google's September Android bulletin. If the date is older, users should check for an available update and install it when their manufacturer releases one.

For businesses, the issue is bigger than one employee postponing an update notification. Security teams managing Android fleets should use mobile device management or unified endpoint management tools to inventory device patch levels and identify phones that are falling behind their manufacturers' support schedules.

Devices that no longer receive security updates deserve particular attention. A phone can continue working normally long after its vendor stops issuing patches, leaving newly discovered vulnerabilities unresolved even when the user believes the device is otherwise up to date.

September's update is therefore a useful reminder to treat Android patch dates as part of endpoint security rather than routine phone maintenance. Check the patch date, install available updates, and determine whether older devices are still receiving vendor support.

For businesses, any unsupported Android device should be identified before the next critical vulnerability turns an aging phone into an avoidable security gap.

Related reading: eSecurity Planet has a full breakdown of Samsung's September Galaxy security update.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.