Google’s September 2026 Android security bulletin patched 180 vulnerabilities, and the one drawing the most alarm from outside researchers does not require a tap, a download or an opened link to work. Tracked as CVE-2026-28662, the flaw sits in the External WPA Supplicant, the component that handles Wi-Fi network authentication, and lets an attacker run code on a phone with no additional privileges and no user interaction at all. Google itself calls the bulletin’s most severe issue a critical System-component bug capable of remote code execution with no extra privileges needed, and 26 of the 180 fixes carry that critical rating.
A flaw in the software that finds Wi-Fi networks
The External WPA Supplicant is the piece of software every Android phone relies on to negotiate a connection with a Wi-Fi network, checking credentials and encryption before a device joins. Because it runs with elevated system access and has to process data from networks a phone has not yet vetted, a memory-corruption bug inside it is unusually dangerous: a nearby attacker does not need the phone’s owner to click anything, install anything or even notice a malicious network is present.
Adam Boynton, a senior enterprise strategy manager at the device-security firm Jamf, singled out the bug directly in comments reported by SecurityWeek. “Most concerning from this list is CVE-2026-28662 because it’s a Wi-Fi-related memory corruption flaw,” Boynton said, adding that if left unpatched, “it could enable attackers to execute code remotely, without any additional privileges or user interaction, potentially allowing privilege escalation.” “It’s crucial that organizations issue the updates across their device fleet as soon as possible,” he said.
180 fixes spread across two patch levels
Google split the September release into two patch levels, according to the Android Security Bulletin published for September 2026. The 2026-09-01 level covers 95 vulnerabilities in the System, Framework and Android Runtime components, including 23 critical System bugs and three critical Framework bugs. The 2026-09-05 level adds another 85 fixes across the kernel and chipset code supplied by hardware partners including Arm, Qualcomm, MediaTek and Unisoc, the vendors whose drivers and firmware sit underneath Android itself. Those vendor-level patches rarely make headlines on their own, since they fix chip-specific bugs rather than a flaw affecting every Android phone at once, but a device running an older or budget chipset can carry a vendor patch gap that persists well after the phone’s own manufacturer has otherwise caught up to Google’s September release.
That split matters because it determines who is actually protected. A phone updated only to the 2026-09-01 patch level has closed most of the System and Framework holes but has not necessarily received the Wi-Fi fix or the kernel and chipset fixes bundled into the second level, depending on which patch level the specific device manufacturer ships. Only a device carrying the 2026-09-05 security patch level or newer has every fix Google issued that month.
Which phones get the fix, and when
Google’s own devices set the pace. The company’s Pixel Update Bulletin for September 2026 confirms that supported Pixel phones receive the 2026-09-05 patch level directly from Google, with firmware images posted for anyone who wants to verify or install the update manually rather than waiting for it to arrive automatically. Phones from other manufacturers depend on each company testing Google’s code against its own hardware and software layers first, a process that has historically taken anywhere from a few days to several months depending on the manufacturer and the device’s age.
The gap between Google’s disclosure and a given phone’s actual patch is what turns a zero-click Wi-Fi flaw from a bulletin item into a real-world risk. A vulnerability that requires no user interaction is, by definition, one a phone’s owner cannot avoid by being careful; the only defense is the patch itself landing on the device, which can take weeks longer on a budget phone from a smaller manufacturer than on a flagship model from a company with a dedicated security-update team.
Checking a phone for the update
Android phones display their current security patch level under the device’s About Phone or Software Update settings menu, alongside the option to check for and install a pending update. Google’s own instructions for updating Android walk through that process for phones running the company’s software, though the exact menu wording varies by manufacturer and version. A patch level dated September 2026 or later means a phone has at least the first wave of this month’s fixes; only 2026-09-05 or newer confirms the Wi-Fi flaw itself has been closed.
Google’s monthly Android bulletins have carried some version of that same warning often enough that Boynton’s advice to patch quickly reads like routine practice, not overreaction. Whether the flaw actually closes on a given phone depends less on Google’s September 9 disclosure than on a manufacturer most owners never think about.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Supplements now rank as the fifth-leading cause of death from liver disease.
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- General Motors is switching on cameras that record inside your vehicle by update
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south