# Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level 2026-10-01)

> Google's Android Security Bulletin for October 2026 (patch level 2026-10-01) fixes 25 vulnerabilities in the Framework and System components, with additional Google Play system update, Pixel and Android Automotive OS fixes. Seven are rated Critical; Google reports no evidence of active exploitation.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3252
- **ID:** TL-2026-3252
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-58865, CVE-2026-55270, CVE-2026-58815, CVE-2026-58841, CVE-2026-58854, CVE-2026-58856, CVE-2026-58834, CVE-2026-55269, CVE-2026-55280, CVE-2026-58835, CVE-2026-58880, CVE-2026-49933, CVE-2026-55265, CVE-2026-49878, CVE-2026-45513, CVE-2026-49880, CVE-2026-49885, CVE-2026-55286, CVE-2026-28667, CVE-2026-45516, CVE-2026-45524, CVE-2026-49937, CVE-2026-55266, CVE-2026-55279, CVE-2026-58859

## Description

The Android Security Bulletin published on 2026-10-05 (v1.0; v1.1 on 2026-10-08 added AOSP links) states that security patch level 2026-10-01 or later addresses all listed issues. SecurityWeek (2026-10-07) reports 25 vulnerabilities: 7 in Framework (1 Critical) and 18 in System (6 Critical), plus 3 Google Play system update (Project Mainline) fixes in Telephony and Wi-Fi, 6 Pixel-specific fixes (3 Critical; Bluetooth, GDMC, GSA) and 5 additional High-severity elevation-of-privilege fixes for Android Automotive OS. Google reports no evidence of active exploitation, and no public PoC is referenced.

The Framework section lists CVE-2026-58865 (Critical, remote DoS with no additional execution privileges; NVD: CVSS 7.5, CWE-119, out-of-bounds bounds check issue in PduParser.java) plus High-severity EoP bugs CVE-2026-55270 (Telephony), CVE-2026-58815, CVE-2026-58856 (audio/video), CVE-2026-58841 (base framework), CVE-2026-58854 (media) and DoS CVE-2026-58834. The System section includes Critical items CVE-2026-55269 (Bluetooth snoop_logger.cc FilterCapturedPacket improper input validation, local EoP, NVD CVSS 7.8, CWE-20, Android 16/16-qpr2/17), CVE-2026-55280 (NFC), CVE-2026-58835 and CVE-2026-58880 (Bluetooth), CVE-2026-49933 (Bluetooth, DoS) and CVE-2026-55265 (PduParser.java out-of-bounds read; bulletin row and NVD classify it as remote DoS, CVSS 6.5, CWE-119, although the SecurityWeek article describes the most severe System issue as local privilege escalation).

The only RCE in the bulletin is CVE-2026-49878 (High; Wi-Fi supplicant, delivered via Project Mainline): an out-of-bounds write in robust_av.c, function wpas_handle_robust_av_scs_recv_action, caused by a logic error, allowing remote code execution with system privileges without user interaction (NVD: CVSS 7.2, CWE-787, AV:N/PR:H). Other High items cover NFC (CVE-2026-45513, CVE-2026-49880, CVE-2026-49885, CVE-2026-55286 ST NFC driver, CVE-2026-28667), information disclosure in FreeType (CVE-2026-45516), Wi-Fi (CVE-2026-45524) and libfmq (CVE-2026-49937), and DoS in the device tree library (CVE-2026-55266), filesystem manager (CVE-2026-55279) and Telephony (CVE-2026-58859).

Data-quality caveat: per-component counts and vulnerability types retrieved from the bulletin page differ slightly from SecurityWeek's totals (e.g. 16 vs 18 System rows in one extraction), so the CVE list above is the retrieved subset and may be incomplete. Pixel and Automotive CVE identifiers were not retrievable (the Pixel bulletin URL returned 404). The cvss_score recorded is the highest NVD score among the four CVEs checked (CVE-2026-55269), not an aggregate for the bulletin. No threat actor, campaign or network infrastructure is associated with these fixes.

## MITRE ATT&CK

- T1404 Exploitation for Privilege Escalation
- T1203 Exploitation for Client Execution
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1664 Exploitation for Initial Access

## Sources

- [Android Security Bulletin - October 2026](https://source.android.com/docs/security/bulletin/2026/2026-10-01)
- [Android's October 2026 Updates Patch 25 Vulnerabilities (SecurityWeek)](https://www.securityweek.com/androids-october-2026-updates-patch-25-vulnerabilities/)
- [NVD - CVE-2026-55269](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55269)
- [NVD - CVE-2026-49878](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-49878)
- [NVD - CVE-2026-58865](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58865)
- [NVD - CVE-2026-55265](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55265)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3252
