Google’s October Android security bulletin fixes 25 vulnerabilities, seven of them rated critical. The company reports no exploitation in the wild for any of the flaws, which are addressed at security patch level 2026-10-01.
What the Android Bulletin Fixes
Google released the bulletin on October 7. It covers the Android Framework, the System component and Play system updates, and it lists separate fixes for Pixel devices and for Android Automotive OS. Of the 25 vulnerabilities, seven are critical: one in Framework and six in System. Android Automotive OS carries five additional high-severity elevation-of-privilege bugs.
The patch level for the release is 2026-10-01. Google reports no in-the-wild exploitation for any of the flaws in the bulletin.
The Critical System Flaw That Allows Local Privilege Escalation
The most severe item is a critical flaw in the Android System component that allows local privilege escalation with no extra execution privileges required. The flaw is local, so it applies to an attacker who already has a presence on the device, but it needs no additional privileges to be exploited.
Android Framework: Five Elevation-of-Privilege Bugs and Two Denial-of-Service Bugs
The Framework section fixes seven vulnerabilities. Five are elevation of privilege flaws and two are denial of service flaws. One Framework flaw is among the seven rated critical across the bulletin.
Android System: Eighteen Flaws Including One Remote Code Execution Bug
The System section is the largest, with 18 flaws. Eight are elevation of privilege bugs, five are denial of service bugs, one is a remote code execution bug and four are information disclosure bugs. Six of the 18 are rated critical, which accounts for most of the bulletin’s critical total.
Play System Updates and Pixel Fixes
Play system updates address three vulnerabilities: one in Telephonycore and two in WiFi. The Pixel section of the bulletin lists six vulnerabilities of its own.
Three Critical Pixel Flaws in Bluetooth, GDMC and GSA
Of the six Pixel flaws, three are critical. They affect the Bluetooth, GDMC and GSA components. Pixel updates are rolling out.
Android Automotive OS Receives Five Additional Fixes
Android Automotive OS, the vehicle version of the platform, carries five additional high-severity elevation-of-privilege bugs that are fixed in this release. These come on top of the fixes that apply to the phone-oriented components, and they are counted separately from the 25.
When Devices Receive Patch Level 2026-10-01
Patch level 2026-10-01 is available now. A broad base of Android devices remains exposed until device makers ship the patch level to their own hardware. Pixel updates are already rolling out, so Google’s own phones are the first to receive the fixes. Other manufacturers distribute the update on their own schedules.
Bulletin Totals by Component
By component, the bulletin’s fixes divide into Framework (7), System (18), Play system updates (3) and Pixel (6). The Framework and System totals add up to the 25 vulnerabilities cited in the headline figure.
The critical ratings are concentrated in System, which holds six of the seven. The remaining critical flaw is in Framework. The three critical Pixel flaws sit in Bluetooth, GDMC and GSA, separate from the Android platform components listed above.
No exploitation has been reported for any item. Google reports that none of the flaws in the October bulletin are being used in attacks, and the fixes now sit in patch level 2026-10-01 for device makers to ship.
The bulletin lists no exploited flaws, and Google attaches no exploitation notice to any of the 25 fixed vulnerabilities. All seven critical flaws, the five Automotive OS bugs and the three critical Pixel bugs are covered by the same patch release cycle.
