Samsung Mobile is releasing a maintenance release for major flagship models as part of monthly Security Maintenance Release (SMR) process. This SMR package includes patches from Google and Samsung.
Google Patches for the following CVEs from Android Security Bulletin are applied in this Security Maintenance Release - September 2026 Package.
Critical
CVE-2026-20499, CVE-2026-28604, CVE-2026-28666, CVE-2026-49918, CVE-2026-49919, CVE-2026-49921, CVE-2026-49926, CVE-2026-49927, CVE-2026-49932, CVE-2026-52993, CVE-2026-55256, CVE-2026-55273, CVE-2026-55277, CVE-2026-58820, CVE-2026-58823, CVE-2026-58846, CVE-2026-58848, CVE-2026-58941
High
CVE-2026-5729, CVE-2026-7476, CVE-2026-7477, CVE-2026-12285, CVE-2026-12387, CVE-2026-20501, CVE-2026-20502, CVE-2026-20503, CVE-2026-24088, CVE-2026-25275, CVE-2026-28572, CVE-2026-28581, CVE-2026-28605, CVE-2026-28607, CVE-2026-28609, CVE-2026-28616, CVE-2026-28617, CVE-2026-28622, CVE-2026-28627, CVE-2026-28636, CVE-2026-28656(A-463364901, A-520523670), CVE-2026-28664, CVE-2026-28668, CVE-2026-28671, CVE-2026-43049, CVE-2026-45517, CVE-2026-45519, CVE-2026-45525, CVE-2026-45527, CVE-2026-45529, CVE-2026-49881, CVE-2026-49883, CVE-2026-49887, CVE-2026-49895, CVE-2026-49913, CVE-2026-55290, CVE-2026-55294, CVE-2026-58822, CVE-2026-58839, CVE-2026-58874
Moderate
None
Already included in previous updates
CVE-2026-20504
Not applicable to Samsung devices
CVE-2025-48651, CVE-2026-4967, CVE-2026-7639, CVE-2026-20500, CVE-2026-21548, CVE-2026-21549, CVE-2026-21550, CVE-2026-21551, CVE-2026-21552, CVE-2026-21553, CVE-2026-21732, CVE-2026-21733, CVE-2026-22164, CVE-2026-22166, CVE-2026-24092, CVE-2026-25294, CVE-2026-28593, CVE-2026-28613, CVE-2026-28626, CVE-2026-31629, CVE-2026-34192, CVE-2026-34193, CVE-2026-34194, CVE-2026-34195, CVE-2026-34196, CVE-2026-41156, CVE-2026-41157, CVE-2026-41158, CVE-2026-45195, CVE-2026-45196, CVE-2026-45197, CVE-2026-45198, CVE-2026-45200, CVE-2026-45202, CVE-2026-45203, CVE-2026-49743, CVE-2026-49744, CVE-2026-49745, CVE-2026-49746, CVE-2026-55285
※ Please see Android Security Bulletin for detailed information on Google patches.
Samsung Semiconductor patch is also included in this Security Maintenance Release for the following CVEs:
High
CVE-2026-48173
※ Please see Samsung Semiconductor Product Security Update for detailed information on Samsung Semiconductor patches.
Along with Google patches and Samsung Semiconductor patches, Samsung Mobile provides 31 Samsung Vulnerabilities and Exposures (SVE) items described below, in order to improve our customer’s confidence on security of Samsung Mobile devices. Samsung security index (SSI), found in “Security software version”, SMR Sep-2026 Release 1 includes all patches from Samsung and Google. Some of the SVE items may not be included in this package, in case these items were already included in a previous maintenance release.
Critical
SVE-2026-3247(CVE-2026-21095)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
The patch adds proper input validation.
SVE-2026-3282(CVE-2026-21096)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
The patch fixed the incorrect implementation.
High
SVE-2026-1849(CVE-2026-21087)
Affected versions: Android 15, 16, 17
Disclosure status: Privately disclosed
Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.
The patch adds proper input validation.
SVE-2026-3217(CVE-2026-21094)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-3314(CVE-2026-21104)
Affected versions: Android 15, 16, 17
Disclosure status: Privately disclosed
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
The patch adds proper input validation.
Moderate
SVE-2026-0168(CVE-2026-21098)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper user interaction.
The patch adds proper access control.
SVE-2026-0828(CVE-2026-21085)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
The patch removes unsafe implementation.
SVE-2026-0885(CVE-2026-21103)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
The patch adds proper input validation.
SVE-2026-1476(CVE-2026-21099)
Affected versions: Android 15, 16, 17
Disclosure status: Privately disclosed
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
The patch adds proper access control.
SVE-2026-1660(CVE-2026-21086)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper authorization in ProxyHandler prior to SMR Sep-2026 Release 1 allows local attackers to access proxy configuration.
The patch adds proper access control.
SVE-2026-1870(CVE-2026-21088)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper validation logic.
SVE-2026-1878(CVE-2026-21089)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper validation logic.
SVE-2026-1989(CVE-2026-21090)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper validation logic.
SVE-2026-2066(CVE-2026-21091)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
The patch adds proper validation logic.
SVE-2026-2233(CVE-2026-21092)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.
The patch adds proper validation logic.
SVE-2026-2314(CVE-2026-21100)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
The patch adds proper access control.
SVE-2026-2461(CVE-2026-21101)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.
The patch adds proper validation logic.
SVE-2026-2687(CVE-2026-21093)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
The patch adds proper input validation.
SVE-2026-3092(CVE-2026-21102)
Affected versions: Android 14, 15, 16, 17
Disclosure status: Privately disclosed
Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
The patch adds proper validation logic.
SVE-2026-3462(CVE-2026-21097)
Affected versions: Android 14,15,16,17
Disclosure status: Privately disclosed
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
The patch adds proper authentication.
Some SVE items included in the Samsung Android Security Update cannot be disclosed at this time.
Acknowledgements
Brendon Tiszka and Mateusz Jurczyk of Google Project Zero: SVE-2026-3247, SVE-2026-3282
Andrew Boni: SVE-2026-3217
k4lizen: SVE-2026-3314
011100101001: SVE-2026-0168
Aleksandr Tarasikov: SVE-2026-0828
Sh1fter: SVE-2026-0885
Ye Zhang (@VAR10CK) of Baidu Security: SVE-2026-1870, SVE-2026-1878, SVE-2026-2066
Fábio Luís / @scanpt: SVE-2026-2233
开源三星实力代购: SVE-2026-2314
Lukas Maar: SVE-2026-2461, SVE-2026-3092
Anton Pakhunov: SVE-2026-2687
Know: SVE-2026-3462
Version
| Version | Date | Notes |
|---|
| 1.0 | Sep 8, 2026 | Bulletin published |