Critical Android Vulnerabilities Affecting Galaxy Devices

Critical Android Vulnerabilities Affecting Galaxy Devices

First seen 9 Sep 2026, 06:44 UTC HkcertEsecurityplanetsource.android.comcve.mitre.org 74.0

Article Content

Browse articles
ThreatCluster

In September 2026, multiple critical vulnerabilities were identified in Android, affecting devices with a security patch level prior to 2026-09-05. The most severe vulnerabilities could enable remote code execution without user interaction. Samsung's September security update addresses 90 vulnerabilities, including 18 critical and 40 high-severity issues from Google's Android Security Bulletin. Notably, CVE-2026-21096 and CVE-2026-21095 involve critical heap-based buffer overflows that could allow remote attackers to execute arbitrary code. Samsung's update also includes fixes for vulnerabilities in their own software components. Users are urged to update their devices to the latest security patch level to mitigate these risks. The Android security team emphasizes the importance of using Google Play Protect to enhance device security. The vulnerabilities affect a wide range of Android devices, particularly Samsung Galaxy models.

Key Points: • 90 vulnerabilities fixed in Samsung's September update, including critical Android flaws. • CVE-2026-21096 and CVE-2026-21095 allow remote code execution without user interaction. • Devices must be updated to security patch level 2026-09-05 or later to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-01
Android Security Bulletin published
Google published a bulletin detailing multiple vulnerabilities affecting Android devices, including critical issues.
source.android.com
2026-09-09
Samsung's September security update released
Samsung released an update addressing 90 vulnerabilities, including critical Android flaws from Google's bulletin.
Esecurityplanet
2026-09-09
CVE-2026-21096 published
A critical heap-based buffer overflow vulnerability affecting DNG image decoding was disclosed.
Hkcert
2026-09-09
CVE-2026-21095 published
A critical heap-based buffer overflow vulnerability affecting JPEG decoding was disclosed.
Hkcert
2026-09-09
CVE-2026-21092 published
A path-traversal vulnerability in ImsService that could allow remote attackers to create image files was disclosed.
Hkcert