Android October 2026 patches: set the right MDM rules
Google's October Android bulletin fixes 25 flaws, 7 critical, none flagged as exploited. Which patch level to require for Pixel, Samsung and the rest.
By Yaali. October 9, 2026, 6 min read, Patching, Mobile, Vulnerabilities.
Google published the Android Security Bulletin for October 2026 on October 5. It fixes 25 vulnerabilities in the Android Framework and System components across Android 14, 15, 16 and 17. Seven are rated Critical and 18 High. The most severe is a Critical elevation of privilege in the System component that an app already on the phone can use without extra permissions or any user interaction. Google does not mark any of the 25 as exploited.
September brought 180 fixes and an exploited Pixel modem bug. October is smaller, and its patch levels need care in compliance rules. All 25 fixes sit at patch level 2026-10-01, and Google published nothing at the usual second level, 2026-10-05. Pixels report 2026-10-05 anyway, Samsung ships its own package, and Pixel 6 and 6 Pro owners have just received their last scheduled update. Each of those needs a slightly different rule in your mobile device management (MDM) tool.

How the October fixes break down
The bulletin splits the 25 fixes into seven in Framework, the Java layer that apps call for windows, permissions and system services, and 18 in System, the native services and libraries underneath. Four of the System bugs are Critical elevations of privilege: CVE-2026-55269, CVE-2026-55280, CVE-2026-58835 and CVE-2026-58880. Elevation of privilege means an app running with ordinary app permissions can gain the rights of a system service and reach data or settings it should not touch. All four affect only Android 16, 16 QPR2 and 17, so older phones on Android 14 or 15 are not exposed to them.
The other three Critical entries are denial-of-service bugs. CVE-2026-58865 in Framework and CVE-2026-55265 in System affect every supported version from Android 14 to 17, while CVE-2026-49933 affects Android 16 and 17. Google rates severity assuming platform mitigations such as the app sandbox have been bypassed, so a Critical rating describes the worst case on an unpatched device. It says nothing about whether anyone is attacking the bug.
The only remote code execution bug, CVE-2026-49878 in the Wi-Fi stack, is rated High and affects Android 14 to 17. Google ships it, along with CVE-2026-45524 (Wi-Fi) and CVE-2026-58859 (Telephony), as a Google Play system update. That channel, also called Project Mainline, updates individual system modules through Google Play without waiting for the phone maker's firmware. It reaches devices on Android 10 and later, including many whose makers have stopped shipping monthly patches. Google has published no technical write-up for any of the 25; the bulletin gained links to the Android Open Source Project (AOSP) source patches on October 8.
What attackers are doing
Nothing public so far. Neither the Android bulletin nor the Pixel bulletin carries the "limited, targeted exploitation" note Google adds when it knows of attacks, and no report we found links any of these CVEs to a campaign. The local elevation of privilege bugs need code on the phone first, which in practice means a malicious app. That suits an attacker who has already got a user to sideload an app, or slipped one past store review. A normal monthly deadline, such as two weeks, fits the risk.
What to do
Know which number each phone should show
The patch level string on a phone is a date. A device at 2026-10-01 or later has all 25 Android bulletin fixes. Google normally adds a second level, 2026-10-05, for Linux kernel and chipset vendor bugs, but PC-WELT notes Google skipped it this month even though Qualcomm published its own October bulletin.
Pixels still report 2026-10-05. The Pixel Update Bulletin, published October 6, adds six Pixel-specific fixes at that level. Three are Critical: CVE-2026-55330 in Bluetooth and CVE-2026-56952 in GDMC, both elevations of privilege, and CVE-2026-55307, an information disclosure in the Google Search app (GSA).
Samsung's October 2026 Security Maintenance Release 1 lists 45 Google patches (9 Critical, 33 High, 3 Moderate), more than the Android bulletin lists. Samsung notes that CVE-2026-28667 and CVE-2026-45513 from the October bulletin were already shipped in earlier Galaxy updates. Rollout started with the newest flagships, including the Galaxy S26 series, and moves model by model and carrier by carrier.
Write the compliance rules per device group
In Microsoft Intune, open Devices, then Compliance, and create or edit an Android Enterprise policy. For fully managed, dedicated and corporate-owned work profile devices, the setting is Minimum security patch level under Device properties. For personally owned work profiles it sits under System security, Device security. Both take a date in YYYY-MM-DD format, and devices below it become noncompliant, which Conditional Access can then use to block work apps. Other Android Enterprise MDMs expose the same patch level field.
A sensible set for October:
- Pixel group: 2026-10-05, with a grace period of 14 days before access is blocked.
- Samsung and other makers: keep your September value for now and raise it to 2026-10-01 once your MDM shows the October build installed on most of each model.
- Everyone: set Play Integrity Verdict under Device health, and on personally owned work profiles also require Google Play Services is configured, the app that delivers Mainline fixes such as the Wi-Fi and Telephony ones above.
A fleet-wide 2026-10-01 rule today would flag every phone whose maker has not shipped October yet and bury the devices that really are behind.
Check a phone by hand
On most Android phones open Settings, About phone, Android version. The screen shows both the Android security update date and the Google Play system update date. A phone can be on a current Play system update but an old security patch, or the reverse; check both. On a Pixel, both sit under Settings, Security & privacy, System & updates. Neither fix is active until the phone restarts.
Pixel 6 and 6 Pro are now out of support
Droid Life and PC-WELT both report that the October update is the last scheduled one for the Pixel 6 and Pixel 6 Pro, which launched in October 2021. Google could still send an emergency fix, but from November these phones will drift below every patch level rule you set. List them in your MDM by model now and plan replacements before they start failing compliance. The Pixel 6a is supported into 2027.
If a phone cannot be updated yet
Google offers no workaround for the Framework and System bugs. Because the elevations of privilege need a local app, the practical control is to restrict where apps come from: Microsoft notes that Android Enterprise devices restrict installs from unknown sources, so check no app policy has opened an exception, and keep Google Play Protect scanning on through a device restriction policy (Device restrictions, System security).
Checking for compromise
There are no published indicators for these CVEs. For a phone that sat unpatched, review the installed app list in your MDM for anything sideloaded or outside your approved catalogue, and check Play Protect alerts on the device. A sudden reboot loop or an app that will not stop crashing is worth a bug report (Developer options, Take bug report) before any reset.
Our safeguarding and hardening work sets up MDM compliance rules and baselines like the ones above, and our mobile penetration testing tests the apps your staff carry and the data they leave on the device. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Android Security Bulletin, October 2026, Pixel Update Bulletin, October 2026, PC-WELT, Samsung Mobile Security, October 2026 SMR, Android Headlines on Samsung's October update, Droid Life on Pixel 6 end of life, Beebom on Pixel 6 end of life, Microsoft Intune Android Enterprise compliance settings, Google Android help: check your Android version.
Read next
- Apple CoreGraphics zero-day: get iPhones to 26.7.1
- Pixel modem zero-day: who to patch first, and how
- Five critical Cisco NX-OS flaws give root on Nexus switches
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.