Samsung’s September 2026 security update fixes 90 vulnerabilities, including critical Galaxy flaws in image decoders. Update now for maximum protectio
Samsung has released its September 2026 security update, addressing a total of 90 vulnerabilities across Galaxy smartphones, tablets, and wearables. This patch is one of the most comprehensive updates of the year, combining fixes from Google’s Android bulletin, Samsung Semiconductor, and Samsung’s own Vulnerabilities & Exposures (SVE) program.
Breakdown of the Update
Google Security Patches
58 vulnerabilities fixed.
18 rated Critical, 40 rated High severity.
40 additional issues listed by Google do not affect Galaxy devices.
Samsung Semiconductor Patch
1 High-severity vulnerability (CVE-2026-48173).
Samsung SVE Fixes
31 Galaxy-specific vulnerabilities.
2 Critical, 3 High, 15 Moderate, 11 undisclosed for security reasons.
Critical Galaxy-Specific Vulnerabilities
CVE-2026-21095 (DNG decoder) – Heap-based buffer overflow.
CVE-2026-21096 (JPEG decoder) – Remote code execution risk.
Both vulnerabilities affect devices running Android 14–17 (One UI 9). They could allow attackers to execute arbitrary code remotely. Samsung has patched these flaws with improved input validation and corrected implementations.
Devices and Rollout
First released via One UI 9 beta for Galaxy A55.
Already live for Galaxy A57 in India, Nepal, Bangladesh, and Sri Lanka.
Expanding soon to Galaxy Z Fold 8, Flip 8, Galaxy S26 series, Galaxy S25 series, and other supported devices.
How to update: Navigate to Settings > Software update > Download and install. Rollout is gradual depending on region and model.
Risks if Unpatched
Remote code execution via image decoders.
Privilege escalation in Android framework/system.
Kernel vulnerabilities affecting Qualcomm, MediaTek, and other drivers.
| Source | Fixes Count | Severity | Examples |
|---|---|---|---|
| 58 | 18 Critical, 40 High | Framework & system flaws | |
| Samsung Semiconductor | 1 | High | CVE-2026-48173 |
| Samsung SVE | 31 | 2 Critical, 3 High, 15 Moderate | DNG/JPEG decoder exploits |
COMMENTS