Google’s October Android Update Patches 7 Critical Security Vulnerabilities

Google’s October Android security update patches seven critical vulnerabilities, including flaws that do not require user interaction.

Written By
Matt Gonzales
Matt Gonzales
Oct 7, 2026
3 minute read
Smartphone displaying the green Android robot logo on a wooden tabletop.

Google’s October Android security update patches seven critical vulnerabilities across the mobile operating system. Image: Generated via Google’s Nano Banana

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Google is patching seven critical Android vulnerabilities, including flaws that could enable privilege escalation or denial-of-service attacks without requiring user interaction.

The company’s October Android Security Bulletin, published Oct. 5, details 25 unique Android vulnerabilities, with seven rated critical. A separate Pixel bulletin identifies six additional security flaws affecting supported Pixel devices.

For security teams managing Android devices, the updates underscore the importance of checking security patch levels rather than assuming devices are protected simply because they are running Android 17.

Seven critical Android vulnerabilities patched

Google’s October Android bulletin identifies seven vulnerabilities rated critical: one in the Framework component and six in the System component.

The Framework vulnerability, CVE-2026-58865, could lead to a remote denial-of-service attack. Google said the most severe vulnerability in the Framework section requires neither additional execution privileges nor user interaction for exploitation. CVE-2026-58865 affects Android 14, 15, 16, 16 QPR2, and 17.

The six critical System vulnerabilities are:

  • CVE-2026-55269: Elevation of privilege
  • CVE-2026-55280: Elevation of privilege
  • CVE-2026-58835: Elevation of privilege
  • CVE-2026-58880: Elevation of privilege
  • CVE-2026-49933: Denial of service
  • CVE-2026-55265: Denial of service

Google said the most severe vulnerability in the System section could lead to local elevation of privilege without additional execution privileges or user interaction.

The company also said newer versions of Android contain security enhancements that make it more difficult to exploit many vulnerabilities and encouraged users to update to the latest Android version available for their devices.

Google pointed to Google Play Protect as another layer of protection against potentially harmful applications, particularly for users who install apps from outside Google Play.

Advertisement

Pixel update fixes three additional critical vulnerabilities

Google’s October Pixel Update Bulletin lists another six vulnerabilities affecting supported Pixel devices.

Three are rated critical:

  • CVE-2026-55330: A critical elevation-of-privilege vulnerability affecting Bluetooth.
  • CVE-2026-56952: A critical elevation-of-privilege vulnerability in the GDMC component.
  • CVE-2026-55307: A critical information-disclosure vulnerability affecting GSA.

The bulletin also lists two high-severity kernel elevation-of-privilege vulnerabilities, CVE-2026-56906 and CVE-2026-56936, and a high-severity information-disclosure vulnerability, CVE-2026-0198, affecting GDMC.

Google’s October Android and Pixel bulletins do not identify any of these vulnerabilities as being actively exploited in the wild.

Supported Pixel devices with a security patch level of Oct. 5, 2026, or later address the vulnerabilities in both the Pixel bulletin and October Android Security Bulletin. Google is encouraging Pixel owners to accept the update when it becomes available.

Android 17 update also fixes Pixel bugs

Google began rolling out its October Android 17 update to supported Pixel devices on Oct. 6, according to 9to5Google.

Beyond the security patches, the update includes three functional fixes. The Pixel 8 through Pixel 11 families receive a fix for an issue that could prevent the virtual keyboard from appearing in certain search fields. Pixel 8 through Pixel 10 families receive a fix for ringtone noise or distortion during certain VoIP calls.

The Pixel 11 family also receives a fix for photos or videos occasionally being saved in the wrong orientation. Google distributes Pixel over-the-air updates gradually, so availability may vary by device and carrier.

Advertisement

Security teams should verify Android patch levels

For organizations managing Android endpoints, the important number in October is the security patch level, not simply the Android version.

Devices declaring the Oct. 1, 2026, security patch level must include fixes for all issues associated with that patch level, as well as fixes for issues reported in previous Android security bulletins. Supported Pixel devices updated to the Oct. 5 patch level address all issues in Google’s October Pixel bulletin and October Android Security Bulletin.

Security teams should inventory managed Android devices, verify their current security patch levels, and, where available, use mobile device management or unified endpoint management tools to identify devices falling behind organizational patch requirements.

The October release follows Google’s September Android security update, which also addressed critical vulnerabilities across Android devices. Keeping track of monthly security patch levels can provide a clearer picture of endpoint exposure than checking the operating system version alone.

Related reading: For more on Android security, see how Android 17 adds new protections designed to preserve evidence of spyware attacks.


Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.