LiMP VPN
All news

Android September 2026 Patch: 180 CVEs, Silent Wi-Fi RCE Exploit

Android September 2026 Patch: 180 CVEs, Silent Wi-Fi RCE Exploit

In short: Google's September 2026 Android security update addresses 180 vulnerabilities. The most critical — CVE-2026-28662 in wpa_supplicant (Wi-Fi) — lets an attacker on the same network execute code on your phone with zero user interaction required. All Android 14–17 devices need this patch immediately.

What happened

In early September 2026, Google released its monthly Android Security Bulletin — and this month's scope was significant: 180 vulnerabilities fixed across two patch levels.

The first patch level (2026-09-01) resolves 95 issues in Android Runtime, Framework, System, Setup Wizard, and Project Mainline modules. The System component alone contained 56 vulnerabilities, 23 of them critical. The second patch level (2026-09-05) adds fixes for 85 more vulnerabilities in the Android kernel and chipmaker components from Arm, Qualcomm, MediaTek, Unisoc, and others.

CVE-2026-28662: the silent Wi-Fi exploit

The headline threat is CVE-2026-28662, a memory corruption bug in wpa_supplicant — Android's Wi-Fi authentication subsystem. It allows an attacker on the same Wi-Fi network to execute arbitrary code on the target device without any user interaction and without elevated privileges.

This means sharing a Wi-Fi network with an adversary at a coffee shop, airport, or shopping mall is potentially enough to compromise an unpatched Android device remotely. The vulnerability affects Android 16, 16-QPR2, and 17.

Beyond CVE-2026-28662, the bulletin documents additional critical RCEs: CVE-2026-28604 (ADB), CVE-2026-28618 (Media/libopenapv), CVE-2026-28639 (NFC), CVE-2026-49921 (Bluetooth), and CVE-2026-52993 (kernel TIPC). The attack surface spans multiple wireless channels — Wi-Fi, Bluetooth, and NFC simultaneously.

Who is affected

The patch is critical for devices running Android 14, 15, 16, 16-QPR2, and 17. Manufacturers began rolling out updates in early September 2026. Samsung, for example, issued its own September 2026 security bulletin addressing 90 vulnerabilities — 40 of them critical — including flaws in Exynos chipset components and KnoxVault.

To update, go to Settings → System → System Update. The patch level is displayed as a date: if it is 2026-09-05 or later, your device is protected. If your manufacturer has not yet released the patch, avoid public Wi-Fi networks until the update arrives.

What this means for your data

The core lesson: open Wi-Fi networks are a genuine threat when devices are unpatched. CVE-2026-28662 requires no phishing, no malicious app — just proximity on the same Wi-Fi network with an attacker.

Learn more about how traffic encryption works on our LiMP VPN features page, and why encrypted connections matter on public networks — plus further analysis in our security blog.

Using an encrypted VPN connection on public Wi-Fi substantially reduces the attack surface: your traffic is encrypted end-to-end before it leaves the device over the air, so even if the vulnerability were exploited, intercepted data would reveal nothing of value.

How to protect yourself

  1. Install the update now: check for patch level 2026-09-05 under device settings.
  2. Avoid public Wi-Fi until the patch is installed, especially in crowded venues.
  3. Enable Google Play Protect: it can neutralize exploit delivery through the Play Store even before a firmware update arrives.
  4. Disable Wi-Fi and Bluetooth when not in use — this shrinks the attack surface for CVE-2026-28662 and CVE-2026-49921.
  5. Use a VPN on public networks: encryption hides traffic content and reduces the value of any data intercepted during possible exploitation.

Sources