Android Google Android Mobile operating system

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Google Android.

Recent Google Android Security Advisories

Advisory Title Published
2026-09-16 Chrome Releases: Chrome for Android Update (version 153) September 16, 2026
2026-09-08 Chrome Releases: Chrome for Android Update (version 153) September 8, 2026
2026-09-04 Chrome Releases: Chrome for Android Update (version 152) September 4, 2026
2026-09-02 Chrome Releases: Chrome for Android (version 152) September 2, 2026
2026-09-01 Android Security Bulletin—September 2026 September 1, 2026
2026-08-26 Chrome Releases: Chrome for Android Update (version 152) August 26, 2026
2026-08-21 Chrome Releases: Chrome for Android Update (version 151) August 21, 2026
2026-08-19 Chrome Releases: Chrome for Android Update (version 151) August 19, 2026
2026-08-12 Chrome Releases: Chrome for Android Update (version 151) August 12, 2026
2026-08-08 Chrome Releases: Chrome for Android Update (version 151) August 8, 2026

EOL Dates

Ensure that you are using a supported version of Google Android. Here are some end of life, and end of support dates for Google Android.

Release EOL Date Status
17 -
Active

16 -
Active

15 -
Active

14 -
Active

13 March 2, 2026
EOL

Google Android 13 became EOL in 2026.

12.1 March 3, 2025
EOL

Google Android 12.1 became EOL in 2025.

12 March 3, 2025
EOL

Google Android 12 became EOL in 2025.

11 February 5, 2024
EOL

Google Android 11 became EOL in 2024.

10 March 6, 2023
EOL

Google Android 10 became EOL in 2023.

9 January 1, 2022
EOL

Google Android 9 became EOL in 2022.

8.1 January 10, 2021
EOL

Google Android 8.1 became EOL in 2021.

8.0 January 1, 2021
EOL

Google Android 8.0 became EOL in 2021.

7.1 October 1, 2019
EOL

Google Android 7.1 became EOL in 2019.

7.0 October 1, 2019
EOL

Google Android 7.0 became EOL in 2019.

6.0 August 1, 2018
EOL

Google Android 6.0 became EOL in 2018.

5.1 March 1, 2018
EOL

Google Android 5.1 became EOL in 2018.

5.0 March 1, 2018
EOL

Google Android 5.0 became EOL in 2018.

4.4w October 1, 2017
EOL

Google Android 4.4w became EOL in 2017.

4.4 October 1, 2017
EOL

Google Android 4.4 became EOL in 2017.

4.3 -
Active

By the Year

In 2026 there have been 559 vulnerabilities in Google Android with an average score of 7.2 out of ten. Last year, in 2025 Android had 450 security vulnerabilities published. That is, 109 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.06




Year Vulnerabilities Average Score
2026 559 7.20
2025 450 7.26
2024 831 7.11
2023 1214 6.45
2022 1048 6.41
2021 575 6.72
2020 702 6.86
2019 491 7.08
2018 432 7.60

It may take a day or so for new Android vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Google Android Security Vulnerabilities

Qualcomm DOS via Transient Frame Parsing in Channel Usage
CVE-2026-25294 7.4 - High - September 17, 2026

Transient DOS while parsing frame during channel usage.

Buffer Over-read

Qualcomm WLAN Driver Transient DoS via Invalid FILS IE Header Length
CVE-2026-25275 7.5 - High - September 17, 2026

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

Buffer Over-read

Qualcomm Bluetooth Transient DOS via Insufficient Channel Map with AFH Enabled
CVE-2026-24081 7.4 - High - September 17, 2026

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

Buffer Over-read

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-58773 6.7 - Medium - September 15, 2026

In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58767 6.7 - Medium - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58766 7.8 - High - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In GPU, there is a possible permission bypass due to a logic error in the code
CVE-2026-58765 6.7 - Medium - September 15, 2026

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58755 6.7 - Medium - September 15, 2026

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2026-58751 6.7 - Medium - September 15, 2026

In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code
CVE-2026-58747 6.7 - Medium - September 15, 2026

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible escalation of privilege due to improper input validation
CVE-2026-58744 7.8 - High - September 15, 2026

In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy
CVE-2026-58739 6.7 - Medium - September 15, 2026

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-58734 7 - High - September 15, 2026

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data
CVE-2026-58731 6.2 - Medium - September 15, 2026

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Use of Uninitialized Variable

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition
CVE-2026-58728 7 - High - September 15, 2026

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Race Condition

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check
CVE-2026-58726 6.7 - Medium - September 15, 2026

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-58724 7 - High - September 15, 2026

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

In multiple locations, there is a possible information disclosure due to uninitialized memory use
CVE-2026-58721 4.4 - Medium - September 15, 2026

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Use of Uninitialized Variable

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation
CVE-2026-58718 6.7 - Medium - September 15, 2026

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition
CVE-2026-58716 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Race Condition

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-58710 8.8 - High - September 15, 2026

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Classic Buffer Overflow

In Cellular Modem, there is a possible permission bypass due to a logic error in the code
CVE-2026-58704 8.8 - High - September 15, 2026

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-58701 7 - High - September 15, 2026

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Race Condition

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check
CVE-2026-58699 8.4 - High - September 15, 2026

In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Out-of-bounds Read

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy
CVE-2026-58698 6.7 - Medium - September 15, 2026

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check
CVE-2026-58695 7.8 - High - September 15, 2026

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Classic Buffer Overflow

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation
CVE-2026-58691 8.4 - High - September 15, 2026

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation
CVE-2026-58683 8.8 - High - September 15, 2026

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code
CVE-2026-58679 8.4 - High - September 15, 2026

In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Heap-based Buffer Overflow

In Bootloader, there is a possible permission bypass due to a logic error in the code
CVE-2026-58678 7.8 - High - September 15, 2026

In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy
CVE-2026-57042 6.7 - Medium - September 15, 2026

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-57035 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-57014 7.8 - High - September 15, 2026

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In the Setup Wizard, there is a possible remote package install due to a missing permission check
CVE-2026-57012 8.4 - High - September 15, 2026

In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In Modem, there is a possible information disclosure due to improper input validation
CVE-2026-57008 7.5 - High - September 15, 2026

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In acfw_ffa.c, there is a possible secret read due to a logic error in the code
CVE-2026-57006 4.4 - Medium - September 15, 2026

In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-56997 8.8 - High - September 15, 2026

In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple files, there is a possible permission bypass due to a confused deputy
CVE-2026-56992 6.7 - Medium - September 15, 2026

In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-56989 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition
CVE-2026-56988 6.4 - Medium - September 15, 2026

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Dangling pointer

In multiple files, there is a possible out-of-bounds read due to type confusion
CVE-2026-56986 8.4 - High - September 15, 2026

In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In multiple files, there is a possible way to obtain signatures due to type confusion
CVE-2026-56985 8.4 - High - September 15, 2026

In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Confused Deputy

In VPU, there is a possible permission bypass due to a missing permission check
CVE-2026-56982 7.8 - High - September 15, 2026

In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible permission bypass due to a logic error in the code
CVE-2026-56979 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check
CVE-2026-56978 8.4 - High - September 15, 2026

In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Classic Buffer Overflow

In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation
CVE-2026-56974 8.8 - High - September 15, 2026

In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

Improper Input Validation

In Cellular Modem, there is a possible denial of service due to improper input validation
CVE-2026-56975 6.5 - Medium - September 15, 2026

In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Improper Input Validation

In multiple locations, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-56973 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check
CVE-2026-56972 6.7 - Medium - September 15, 2026

In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Memory Corruption

In multiple locations, there is a possible permission bypass due to a missing permission check
CVE-2026-56970 8.4 - High - September 15, 2026

In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Protection Mechanism Failure

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Google Android or by Google? Click the Watch button to subscribe.

Google
Vendor

Google Android
Mobile operating system

subscribe