Threat reportVulnerabilityTL-2026-3252
Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level 2026-10-01)
Android October 2026 Security Bulletin (TL-2026-3252), also tracked as Android Security Bulletin October 2026, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-10-10. It has no confirmed attribution, affects Google Android (AOSP), references 25 CVEs (CVE-2026-58865, CVE-2026-55270, CVE-2026-58815), maps to 4 MITRE ATT&CK techniques (T1203, T1404, T1499.004), and is covered by 9 detection rules and 7 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 25Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-3252
- Threat ID
- TL-2026-3252
- Also known as
- Android Security Bulletin October 2026, Android patch level 2026-10-01
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, automotive, telecoms, government administration, finance, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
How Android October 2026 Security Bulletin works
Google's Android Security Bulletin for October 2026 (patch level 2026-10-01) fixes 25 vulnerabilities in the Framework and System components, with additional Google Play system update, Pixel and Android Automotive OS fixes. Seven are rated Critical; Google reports no evidence of active exploitation.
The Android Security Bulletin published on 2026-10-05 (v1.0; v1.1 on 2026-10-08 added AOSP links) states that security patch level 2026-10-01 or later addresses all listed issues. SecurityWeek (2026-10-07) reports 25 vulnerabilities: 7 in Framework (1 Critical) and 18 in System (6 Critical), plus 3 Google Play system update (Project Mainline) fixes in Telephony and Wi-Fi, 6 Pixel-specific fixes (3 Critical; Bluetooth, GDMC, GSA) and 5 additional High-severity elevation-of-privilege fixes for Android Automotive OS. Google reports no evidence of active exploitation, and no public PoC is referenced.
The Framework section lists CVE-2026-58865 (Critical, remote DoS with no additional execution privileges; NVD: CVSS 7.5, CWE-119, out-of-bounds bounds check issue in PduParser.java) plus High-severity EoP bugs CVE-2026-55270 (Telephony), CVE-2026-58815, CVE-2026-58856 (audio/video), CVE-2026-58841 (base framework), CVE-2026-58854 (media) and DoS CVE-2026-58834. The System section includes Critical items CVE-2026-55269 (Bluetooth snoop_logger.cc FilterCapturedPacket improper input validation, local EoP, NVD CVSS 7.8, CWE-20, Android 16/16-qpr2/17), CVE-2026-55280 (NFC), CVE-2026-58835 and CVE-2026-58880 (Bluetooth), CVE-2026-49933 (Bluetooth, DoS) and CVE-2026-55265 (PduParser.java out-of-bounds read; bulletin row and NVD classify it as remote DoS, CVSS 6.5, CWE-119, although the SecurityWeek article describes the most severe System issue as local privilege escalation).
The only RCE in the bulletin is CVE-2026-49878 (High; Wi-Fi supplicant, delivered via Project Mainline): an out-of-bounds write in robust_av.c, function wpas_handle_robust_av_scs_recv_action, caused by a logic error, allowing remote code execution with system privileges without user interaction (NVD: CVSS 7.2, CWE-787, AV:N/PR:H). Other High items cover NFC (CVE-2026-45513, CVE-2026-49880, CVE-2026-49885, CVE-2026-55286 ST NFC driver, CVE-2026-28667), information disclosure in FreeType (CVE-2026-45516), Wi-Fi (CVE-2026-45524) and libfmq (CVE-2026-49937), and DoS in the device tree library (CVE-2026-55266), filesystem manager (CVE-2026-55279) and Telephony (CVE-2026-58859).
Data-quality caveat: per-component counts and vulnerability types retrieved from the bulletin page differ slightly from SecurityWeek's totals (e.g. 16 vs 18 System rows in one extraction), so the CVE list above is the retrieved subset and may be incomplete. Pixel and Automotive CVE identifiers were not retrievable (the Pixel bulletin URL returned 404). The cvss_score recorded is the highest NVD score among the four CVEs checked (CVE-2026-55269), not an aggregate for the bulletin. No threat actor, campaign or network infrastructure is associated with these fixes.
MITRE ATT&CK techniques used in TL-2026-3252
Execution
T1203 Exploitation for Client Execution
privilege-escalation
T1404 Exploitation for Privilege Escalation
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
initial-access
Affected products and versions in Android October 2026 Security Bulletin
- Google — Android (AOSP)
Vulnerable versions: 14; 15; 16; 16-qpr2; 17
Fixed in: Security patch level 2026-10-01 or later - Google — Pixel devices
Vulnerable versions: Pixel devices prior to the October 2026 update
Fixed in: Pixel October 2026 security update - Google — Android Automotive OS
Vulnerable versions: Android Automotive OS builds without the October 2026 fixes
Fixed in: Builds including patch level 2026-10-01 and the 5 additional AAOS fixes
Remediation for Android October 2026 Security Bulletin
Patches
- Android Security Bulletin October 2026, patch level 2026-10-01 (Framework, System, Google Play system updates)
- Pixel October 2026 update and Android Automotive OS updates from the OEM/vendor
Immediate actions
- Deploy Android security patch level 2026-10-01 or later to all managed devices
- Verify patch level via Settings > About phone > Android version > Android security update, or MDM compliance reports
Workarounds
- Disable Bluetooth and NFC on unpatched devices when not in use
- Avoid untrusted Wi-Fi networks on unpatched devices
Longer-term hardening
- Enforce MDM compliance policies that require a maximum patch-level age for Android devices
- Keep Google Play system updates (Project Mainline) enabled so Wi-Fi and Telephony fixes are delivered
CVEs associated with Android October 2026 Security Bulletin
CVE-2026-58865CVE-2026-55270CVE-2026-58815CVE-2026-58841CVE-2026-58854CVE-2026-58856CVE-2026-58834CVE-2026-55269CVE-2026-55280CVE-2026-58835CVE-2026-58880CVE-2026-49933CVE-2026-55265CVE-2026-49878CVE-2026-45513CVE-2026-49880CVE-2026-49885CVE-2026-55286CVE-2026-28667CVE-2026-45516CVE-2026-45524CVE-2026-49937CVE-2026-55266CVE-2026-55279CVE-2026-58859
Weaknesses (CWE) in Android October 2026 Security Bulletin
Timeline of Android October 2026 Security Bulletin
- Android security patch level 2026-10-01 defined as the baseline that addresses all issues listed in the October 2026 bulletin
- Bulletin flags a Critical System flaw enabling local privilege escalation with no additional execution privileges and no user interaction (CVE-2026-55269 and related Critical System EoP items CVE-2026-55280, CVE-2026-58835, CVE-2026-58880)
- Google Play system updates (Project Mainline) ship 3 fixes in Telephonycore (CVE-2026-58859) and Wi-Fi (CVE-2026-45524, CVE-2026-49878 RCE), deliverable independently of the full OTA patch level
- NVD publishes entries for bulletin CVEs, e.g. CVE-2026-55269 (CVSS 7.8), CVE-2026-49878 (CVSS 7.2), CVE-2026-58865 (CVSS 7.5), CVE-2026-55265 (CVSS 6.5)
- Android Security Bulletin October 2026 v1.0 published, listing Framework, System and Google Play system update fixes
- SecurityWeek breakdown: Framework 7 bugs (5 EoP, 2 DoS), System 18 bugs (8 EoP, 5 DoS, 1 RCE, 4 ID); plus 6 Pixel fixes (3 Critical; Bluetooth, GDMC, GSA) and 5 additional High EoP fixes for Android Automotive OS
- SecurityWeek reports 25 patched vulnerabilities, 7 Critical, with no evidence of active exploitation
- Bulletin v1.1 published with AOSP source patch links added
- As of research cut-off, no public PoC and no evidence of in-the-wild exploitation reported for any October 2026 Android bulletin CVE; status remains PATCHED
Sources cited for Android October 2026 Security Bulletin
Detection coverage for TL-2026-3252
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3252 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.