Google Android Mobile operating system
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Google Android.
Recent Google Android Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-16 | Chrome Releases: Chrome for Android Update (version 153) | September 16, 2026 |
| 2026-09-08 | Chrome Releases: Chrome for Android Update (version 153) | September 8, 2026 |
| 2026-09-04 | Chrome Releases: Chrome for Android Update (version 152) | September 4, 2026 |
| 2026-09-02 | Chrome Releases: Chrome for Android (version 152) | September 2, 2026 |
| 2026-09-01 | Android Security Bulletin—September 2026 | September 1, 2026 |
| 2026-08-26 | Chrome Releases: Chrome for Android Update (version 152) | August 26, 2026 |
| 2026-08-21 | Chrome Releases: Chrome for Android Update (version 151) | August 21, 2026 |
| 2026-08-19 | Chrome Releases: Chrome for Android Update (version 151) | August 19, 2026 |
| 2026-08-12 | Chrome Releases: Chrome for Android Update (version 151) | August 12, 2026 |
| 2026-08-08 | Chrome Releases: Chrome for Android Update (version 151) | August 8, 2026 |
EOL Dates
Ensure that you are using a supported version of Google Android. Here are some end of life, and end of support dates for Google Android.
| Release | EOL Date | Status |
|---|---|---|
| 17 | - |
Active
|
| 16 | - |
Active
|
| 15 | - |
Active
|
| 14 | - |
Active
|
| 13 | March 2, 2026 |
EOL
Google Android 13 became EOL in 2026. |
| 12.1 | March 3, 2025 |
EOL
Google Android 12.1 became EOL in 2025. |
| 12 | March 3, 2025 |
EOL
Google Android 12 became EOL in 2025. |
| 11 | February 5, 2024 |
EOL
Google Android 11 became EOL in 2024. |
| 10 | March 6, 2023 |
EOL
Google Android 10 became EOL in 2023. |
| 9 | January 1, 2022 |
EOL
Google Android 9 became EOL in 2022. |
| 8.1 | January 10, 2021 |
EOL
Google Android 8.1 became EOL in 2021. |
| 8.0 | January 1, 2021 |
EOL
Google Android 8.0 became EOL in 2021. |
| 7.1 | October 1, 2019 |
EOL
Google Android 7.1 became EOL in 2019. |
| 7.0 | October 1, 2019 |
EOL
Google Android 7.0 became EOL in 2019. |
| 6.0 | August 1, 2018 |
EOL
Google Android 6.0 became EOL in 2018. |
| 5.1 | March 1, 2018 |
EOL
Google Android 5.1 became EOL in 2018. |
| 5.0 | March 1, 2018 |
EOL
Google Android 5.0 became EOL in 2018. |
| 4.4w | October 1, 2017 |
EOL
Google Android 4.4w became EOL in 2017. |
| 4.4 | October 1, 2017 |
EOL
Google Android 4.4 became EOL in 2017. |
| 4.3 | - |
Active
|
By the Year
In 2026 there have been 559 vulnerabilities in Google Android with an average score of 7.2 out of ten. Last year, in 2025 Android had 450 security vulnerabilities published. That is, 109 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.06
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 559 | 7.20 |
| 2025 | 450 | 7.26 |
| 2024 | 831 | 7.11 |
| 2023 | 1214 | 6.45 |
| 2022 | 1048 | 6.41 |
| 2021 | 575 | 6.72 |
| 2020 | 702 | 6.86 |
| 2019 | 491 | 7.08 |
| 2018 | 432 | 7.60 |
It may take a day or so for new Android vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Android Security Vulnerabilities
Qualcomm DOS via Transient Frame Parsing in Channel Usage
CVE-2026-25294
7.4 - High
- September 17, 2026
Transient DOS while parsing frame during channel usage.
Buffer Over-read
Qualcomm WLAN Driver Transient DoS via Invalid FILS IE Header Length
CVE-2026-25275
7.5 - High
- September 17, 2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Buffer Over-read
Qualcomm Bluetooth Transient DOS via Insufficient Channel Map with AFH Enabled
CVE-2026-24081
7.4 - High
- September 17, 2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Buffer Over-read
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-58773
6.7 - Medium
- September 15, 2026
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58767
6.7 - Medium
- September 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58766
7.8 - High
- September 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In GPU, there is a possible permission bypass due to a logic error in the code
CVE-2026-58765
6.7 - Medium
- September 15, 2026
In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-58755
6.7 - Medium
- September 15, 2026
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2026-58751
6.7 - Medium
- September 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Dangling pointer
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code
CVE-2026-58747
6.7 - Medium
- September 15, 2026
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple locations, there is a possible escalation of privilege due to improper input validation
CVE-2026-58744
7.8 - High
- September 15, 2026
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy
CVE-2026-58739
6.7 - Medium
- September 15, 2026
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-58734
7 - High
- September 15, 2026
In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data
CVE-2026-58731
6.2 - Medium
- September 15, 2026
In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Use of Uninitialized Variable
In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition
CVE-2026-58728
7 - High
- September 15, 2026
In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Race Condition
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check
CVE-2026-58726
6.7 - Medium
- September 15, 2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-58724
7 - High
- September 15, 2026
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Dangling pointer
In multiple locations, there is a possible information disclosure due to uninitialized memory use
CVE-2026-58721
4.4 - Medium
- September 15, 2026
In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Use of Uninitialized Variable
In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation
CVE-2026-58718
6.7 - Medium
- September 15, 2026
In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In multiple locations, there is a possible time-of-check to time-of-use due to a race condition
CVE-2026-58716
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Race Condition
In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-58710
8.8 - High
- September 15, 2026
In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Classic Buffer Overflow
In Cellular Modem, there is a possible permission bypass due to a logic error in the code
CVE-2026-58704
8.8 - High
- September 15, 2026
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition
CVE-2026-58701
7 - High
- September 15, 2026
In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Race Condition
In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check
CVE-2026-58699
8.4 - High
- September 15, 2026
In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Out-of-bounds Read
In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy
CVE-2026-58698
6.7 - Medium
- September 15, 2026
In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check
CVE-2026-58695
7.8 - High
- September 15, 2026
In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Classic Buffer Overflow
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation
CVE-2026-58691
8.4 - High
- September 15, 2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation
CVE-2026-58683
8.8 - High
- September 15, 2026
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code
CVE-2026-58679
8.4 - High
- September 15, 2026
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Heap-based Buffer Overflow
In Bootloader, there is a possible permission bypass due to a logic error in the code
CVE-2026-58678
7.8 - High
- September 15, 2026
In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy
CVE-2026-57042
6.7 - Medium
- September 15, 2026
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-57035
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-57014
7.8 - High
- September 15, 2026
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In the Setup Wizard, there is a possible remote package install due to a missing permission check
CVE-2026-57012
8.4 - High
- September 15, 2026
In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In Modem, there is a possible information disclosure due to improper input validation
CVE-2026-57008
7.5 - High
- September 15, 2026
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In acfw_ffa.c, there is a possible secret read due to a logic error in the code
CVE-2026-57006
4.4 - Medium
- September 15, 2026
In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-56997
8.8 - High
- September 15, 2026
In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In multiple files, there is a possible permission bypass due to a confused deputy
CVE-2026-56992
6.7 - Medium
- September 15, 2026
In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check
CVE-2026-56989
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition
CVE-2026-56988
6.4 - Medium
- September 15, 2026
In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Dangling pointer
In multiple files, there is a possible out-of-bounds read due to type confusion
CVE-2026-56986
8.4 - High
- September 15, 2026
In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In multiple files, there is a possible way to obtain signatures due to type confusion
CVE-2026-56985
8.4 - High
- September 15, 2026
In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Confused Deputy
In VPU, there is a possible permission bypass due to a missing permission check
CVE-2026-56982
7.8 - High
- September 15, 2026
In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple locations, there is a possible permission bypass due to a logic error in the code
CVE-2026-56979
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check
CVE-2026-56978
8.4 - High
- September 15, 2026
In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Classic Buffer Overflow
In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation
CVE-2026-56974
8.8 - High
- September 15, 2026
In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Improper Input Validation
In Cellular Modem, there is a possible denial of service due to improper input validation
CVE-2026-56975
6.5 - Medium
- September 15, 2026
In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Improper Input Validation
In multiple locations, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-56973
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check
CVE-2026-56972
6.7 - Medium
- September 15, 2026
In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Memory Corruption
In multiple locations, there is a possible permission bypass due to a missing permission check
CVE-2026-56970
8.4 - High
- September 15, 2026
In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Protection Mechanism Failure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Google Android or by Google? Click the Watch button to subscribe.