Google Patches 180 Android Flaws, Including a Wi-Fi Bug That Needs No Tap to Exploit
September 2026's Android security update is the largest in months. One flaw in particular lets attackers run malicious code over Wi-Fi without the phone's owner doing anything at all.

Key points
- Google released patches for 180 Android security flaws on 2 September 2026, the platform's biggest update after two quiet months.
- The most dangerous flaw, CVE-2026-28662, sits in Android's Wi-Fi code and lets an attacker run software on your phone without you clicking anything.
- 23 of the patched bugs are rated "critical" severity and live in Android's System component, which controls core phone functions.
- Phones showing a security patch level of 2026-09-05 or later contain fixes for every flaw listed in this bulletin.
- Wear OS, Android XR, and Android Automotive OS receive no separate patches this month but inherit all fixes through their normal updates.
Google has pushed its largest Android security update in months, closing 180 vulnerabilities, which are software flaws that attackers can use to break into or disrupt a device, across the Android operating system. The company published its September 2026 Android Security Bulletin on Tuesday after issuing no security fixes at all in July or August.
Why does the Wi-Fi bug matter most?
One flaw, CVE-2026-28662, stands out. It is a memory-corruption bug, a flaw where software mishandles data in a way that lets an outsider take control, hidden inside Android's Wi-Fi code. An attacker on the same Wi-Fi network could use it to silently run their own software on your phone, no tap, no link click, no warning required.
Adam Boynton, senior enterprise strategy manager at mobile-device security firm Jamf, called it the most concerning item on the list. "If left unpatched, it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation," he said. Privilege escalation means an attacker moves from limited access to full control of the device.
What exactly did Google fix?
The update ships in two waves.
| Patch level | Bugs fixed | Highest severity | Components covered |
|---|---|---|---|
| 2026-09-01 | 95 | Critical | System, Framework, Android Runtime, Setup Wizard, Mainline |
| 2026-09-05 | 85 | Critical | Kernel, Qualcomm, MediaTek, Arm, Unisoc, others |
The System component alone accounts for 56 fixes, 23 of them critical. Those bugs could allow remote code execution (RCE), meaning an outsider runs code on your device, elevation of privilege, or denial-of-service attacks that crash the phone. Framework, which governs how apps talk to Android, contributed another 37 fixes including three critical ones.
The second patch wave covers chips and hardware components from suppliers including Qualcomm, MediaTek, Arm, and Unisoc. Devices updated to patch level 2026-09-05 or later receive every fix from both waves.
Should ordinary Android users do anything?
Yes, one thing: check for an update and install it. On most Android phones, go to Settings, then About Phone, then Software Update. If your phone shows a security patch date of 2026-09-05 or later, you are covered.
Not every phone receives patches immediately. Manufacturers such as Samsung and Nokia test Google's fixes before pushing them to their own devices, which can add days or weeks. If your phone is several years old, a patch may never arrive at all, which is worth knowing.
Google has not said any of these 180 flaws are actively being exploited right now, as reported by SecurityWeek. That is some comfort, but the window between a public patch and criminals reverse-engineering it to attack unpatched phones is typically short. Update promptly.



