Threat reportVulnerabilityTL-2026-3252

Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level 2026-10-01)

highPATCHED

Android October 2026 Security Bulletin (TL-2026-3252), also tracked as Android Security Bulletin October 2026, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-10-10. It has no confirmed attribution, affects Google Android (AOSP), references 25 CVEs (CVE-2026-58865, CVE-2026-55270, CVE-2026-58815), maps to 4 MITRE ATT&CK techniques (T1203, T1404, T1499.004), and is covered by 9 detection rules and 7 indicators of compromise.

CVSS
7.8/10High
CVEs
25Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-3252

Threat ID
TL-2026-3252
Also known as
Android Security Bulletin October 2026, Android patch level 2026-10-01
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, automotive, telecoms, government administration, finance, health
Target regions
Global
Detection rules
9
Indicators of compromise
7

How Android October 2026 Security Bulletin works

Google's Android Security Bulletin for October 2026 (patch level 2026-10-01) fixes 25 vulnerabilities in the Framework and System components, with additional Google Play system update, Pixel and Android Automotive OS fixes. Seven are rated Critical; Google reports no evidence of active exploitation.

The Android Security Bulletin published on 2026-10-05 (v1.0; v1.1 on 2026-10-08 added AOSP links) states that security patch level 2026-10-01 or later addresses all listed issues. SecurityWeek (2026-10-07) reports 25 vulnerabilities: 7 in Framework (1 Critical) and 18 in System (6 Critical), plus 3 Google Play system update (Project Mainline) fixes in Telephony and Wi-Fi, 6 Pixel-specific fixes (3 Critical; Bluetooth, GDMC, GSA) and 5 additional High-severity elevation-of-privilege fixes for Android Automotive OS. Google reports no evidence of active exploitation, and no public PoC is referenced.

The Framework section lists CVE-2026-58865 (Critical, remote DoS with no additional execution privileges; NVD: CVSS 7.5, CWE-119, out-of-bounds bounds check issue in PduParser.java) plus High-severity EoP bugs CVE-2026-55270 (Telephony), CVE-2026-58815, CVE-2026-58856 (audio/video), CVE-2026-58841 (base framework), CVE-2026-58854 (media) and DoS CVE-2026-58834. The System section includes Critical items CVE-2026-55269 (Bluetooth snoop_logger.cc FilterCapturedPacket improper input validation, local EoP, NVD CVSS 7.8, CWE-20, Android 16/16-qpr2/17), CVE-2026-55280 (NFC), CVE-2026-58835 and CVE-2026-58880 (Bluetooth), CVE-2026-49933 (Bluetooth, DoS) and CVE-2026-55265 (PduParser.java out-of-bounds read; bulletin row and NVD classify it as remote DoS, CVSS 6.5, CWE-119, although the SecurityWeek article describes the most severe System issue as local privilege escalation).

The only RCE in the bulletin is CVE-2026-49878 (High; Wi-Fi supplicant, delivered via Project Mainline): an out-of-bounds write in robust_av.c, function wpas_handle_robust_av_scs_recv_action, caused by a logic error, allowing remote code execution with system privileges without user interaction (NVD: CVSS 7.2, CWE-787, AV:N/PR:H). Other High items cover NFC (CVE-2026-45513, CVE-2026-49880, CVE-2026-49885, CVE-2026-55286 ST NFC driver, CVE-2026-28667), information disclosure in FreeType (CVE-2026-45516), Wi-Fi (CVE-2026-45524) and libfmq (CVE-2026-49937), and DoS in the device tree library (CVE-2026-55266), filesystem manager (CVE-2026-55279) and Telephony (CVE-2026-58859).

Data-quality caveat: per-component counts and vulnerability types retrieved from the bulletin page differ slightly from SecurityWeek's totals (e.g. 16 vs 18 System rows in one extraction), so the CVE list above is the retrieved subset and may be incomplete. Pixel and Automotive CVE identifiers were not retrievable (the Pixel bulletin URL returned 404). The cvss_score recorded is the highest NVD score among the four CVEs checked (CVE-2026-55269), not an aggregate for the bulletin. No threat actor, campaign or network infrastructure is associated with these fixes.

MITRE ATT&CK techniques used in TL-2026-3252

Execution

T1203 Exploitation for Client Execution

privilege-escalation

T1404 Exploitation for Privilege Escalation

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

initial-access

T1664 Exploitation for Initial Access

Affected products and versions in Android October 2026 Security Bulletin

  • Google — Android (AOSP)
    Vulnerable versions: 14; 15; 16; 16-qpr2; 17
    Fixed in: Security patch level 2026-10-01 or later
  • Google — Pixel devices
    Vulnerable versions: Pixel devices prior to the October 2026 update
    Fixed in: Pixel October 2026 security update
  • Google — Android Automotive OS
    Vulnerable versions: Android Automotive OS builds without the October 2026 fixes
    Fixed in: Builds including patch level 2026-10-01 and the 5 additional AAOS fixes

Remediation for Android October 2026 Security Bulletin

Patches

  • Android Security Bulletin October 2026, patch level 2026-10-01 (Framework, System, Google Play system updates)
  • Pixel October 2026 update and Android Automotive OS updates from the OEM/vendor

Immediate actions

  • Deploy Android security patch level 2026-10-01 or later to all managed devices
  • Verify patch level via Settings > About phone > Android version > Android security update, or MDM compliance reports

Workarounds

  • Disable Bluetooth and NFC on unpatched devices when not in use
  • Avoid untrusted Wi-Fi networks on unpatched devices

Longer-term hardening

  • Enforce MDM compliance policies that require a maximum patch-level age for Android devices
  • Keep Google Play system updates (Project Mainline) enabled so Wi-Fi and Telephony fixes are delivered

CVEs associated with Android October 2026 Security Bulletin

  • CVE-2026-58865
  • CVE-2026-55270
  • CVE-2026-58815
  • CVE-2026-58841
  • CVE-2026-58854
  • CVE-2026-58856
  • CVE-2026-58834
  • CVE-2026-55269
  • CVE-2026-55280
  • CVE-2026-58835
  • CVE-2026-58880
  • CVE-2026-49933
  • CVE-2026-55265
  • CVE-2026-49878
  • CVE-2026-45513
  • CVE-2026-49880
  • CVE-2026-49885
  • CVE-2026-55286
  • CVE-2026-28667
  • CVE-2026-45516
  • CVE-2026-45524
  • CVE-2026-49937
  • CVE-2026-55266
  • CVE-2026-55279
  • CVE-2026-58859

Weaknesses (CWE) in Android October 2026 Security Bulletin

CWE-119, CWE-20, CWE-787

Timeline of Android October 2026 Security Bulletin

  • Android security patch level 2026-10-01 defined as the baseline that addresses all issues listed in the October 2026 bulletin
  • Bulletin flags a Critical System flaw enabling local privilege escalation with no additional execution privileges and no user interaction (CVE-2026-55269 and related Critical System EoP items CVE-2026-55280, CVE-2026-58835, CVE-2026-58880)
  • Google Play system updates (Project Mainline) ship 3 fixes in Telephonycore (CVE-2026-58859) and Wi-Fi (CVE-2026-45524, CVE-2026-49878 RCE), deliverable independently of the full OTA patch level
  • NVD publishes entries for bulletin CVEs, e.g. CVE-2026-55269 (CVSS 7.8), CVE-2026-49878 (CVSS 7.2), CVE-2026-58865 (CVSS 7.5), CVE-2026-55265 (CVSS 6.5)
  • Android Security Bulletin October 2026 v1.0 published, listing Framework, System and Google Play system update fixes
  • SecurityWeek breakdown: Framework 7 bugs (5 EoP, 2 DoS), System 18 bugs (8 EoP, 5 DoS, 1 RCE, 4 ID); plus 6 Pixel fixes (3 Critical; Bluetooth, GDMC, GSA) and 5 additional High EoP fixes for Android Automotive OS
  • SecurityWeek reports 25 patched vulnerabilities, 7 Critical, with no evidence of active exploitation
  • Bulletin v1.1 published with AOSP source patch links added
  • As of research cut-off, no public PoC and no evidence of in-the-wild exploitation reported for any October 2026 Android bulletin CVE; status remains PATCHED

Sources cited for Android October 2026 Security Bulletin

Detection coverage for TL-2026-3252

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3252 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats