Google published the October 2026 Android Security Bulletin on October 5, patching 25 vulnerabilities across the Framework and System components. Seven of them are rated Critical, and six of those sit in Bluetooth and NFC code that an attacker can trigger without extra app permissions or any help from the user. Google has not reported active exploitation of any of these flaws. The patch level is 2026-10-01, and it is already rolling out to devices on their normal OEM update schedule.
What the Critical Flaws Actually Touch
One Critical bug, CVE-2026-58865, sits in the Framework and allows a remote denial of service with no extra execution privileges needed. The other six are all in System, and four of them are Bluetooth issues: CVE-2026-55269, CVE-2026-58835, and CVE-2026-58880 are local privilege escalation bugs, and CVE-2026-49933 is a denial of service. A fifth, CVE-2026-55280, is an NFC privilege escalation flaw, and the sixth, CVE-2026-55265, is a System-level denial of service. None of them require user interaction to exploit, which is the detail that pushes them into Critical rather than High.
Beyond the seven Critical entries, the bulletin lists 18 High-severity fixes split between Framework and System. Google’s own bulletin doesn’t flag any of the 25 as under active attack, which is worth noting given how often this category of monthly roundup gets treated as an emergency when it isn’t one.
Who Should Actually Care
This isn’t a one-click-takeover story the way some of the zero-days covered on this blog have been. It’s a routine, if unusually Bluetooth-heavy, monthly patch cycle. The people who should pay attention are teams building or maintaining apps that lean on Bluetooth or NFC specifically: proximity features, hardware pairing, tap-to-pay, access control integrations. If your app touches any of those, it’s worth confirming your test devices are on patch level 2026-10-01 or later before the next release goes out, since OEMs stagger rollout and some users will be on the old patch level for weeks.
For most other apps, this is a “let the update land” month rather than a “stop and patch something” month. That said, this is also a reasonable prompt to check whether an app’s target SDK and dependency versions are current rather than waiting for the next scary CVE to force the question. We walked through exactly that kind of tradeoff in a recent build, covered in Native vs. Cross-Platform for a POS App: What a 4-Week Flutter Build Showed Us, where device-level compatibility across Android versions was a real part of the decision.
What To Do Now
- Check your test devices and CI emulators are running patch level 2026-10-01 or newer.
- If your app uses Bluetooth pairing or NFC (payments, access badges, proximity triggers), re-test those flows after the update lands rather than assuming nothing changed.
- Don’t rush a hotfix release over this bulletin specifically. Nothing here is confirmed exploited, and the fixes land through the normal OS update, not an app-side patch.
If a mobile app development partner hasn’t checked your app against this patch level yet, it’s a quick audit, not a rebuild. We’ve run this kind of compatibility pass across several Android and cross-platform builds and it usually takes a day, not a sprint.
Sources
- Android Security Bulletin, October 2026 (source.android.com, official Google bulletin)



