Want to know what is in the August Android security update? Ask Samsung, not Google.
Anadolu Agency via Getty Images
The August 2026 Android update has dropped, and Google has published the accompanying announcement that stated: “This Android Security Bulletin contains details of security vulnerabilities that affect Android devices.” Which is great, except that it doesn’t. The August 3 bulletin has absolutely zero Common Vulnerabilities and Exposures listed, nor any hint of how many might have been fixed. The same lack of CVE information has started to occur with Chrome browser update notifications as well, with the update announcement being made and then CVE details arriving 24 or even 48 hours later. I have approached Google for a statement as to why this might be, but in the meantime, cybersecurity enthusiasts, Samsung has your back. The latest monthly Security Maintenance Release bulletin for Galaxy smartphone users has listed them all. As well as detailing 18 fixed Samsung Vulnerabilities and Exposures, yes, they do call them that, the bulletin also confirms there are 38 CVEs provided by Google in the fix. Of these, eight carry a Common Vulnerability Scoring System severity rating of critical, while the remaining 30 are listed as being high-rated.
What Are The Critical Android CVEs That Samsung Has Confirmed?
Here is the full list of critical Android CVEs that have been fixed in the August security update, with as much detail as I was able to confirm at this point in time:
- CVE-2026-25289 is a memory corruption in Android’s Neighbor Awareness Networking Service.
- CVE-2026-28662 is an improper input validation issue, but that’s all the detail I was able to find.
- CVE-2026-45515 can allow an attacker, with local access, to cause device inoperability and launch arbitrary activity.
- CVE-2026-49882 appears to be an input validation issue that impacts the dialer application on Android 14, 15, and 16 devices.
I was unable to uncover any further information about CVE-2026-28591, CVE-2026-28653, CVE-2026-49879 or CVE-2026-49884. I will update this article once Google and the various vulnerability monitoring databases have provided any information.
What Android And Samsung Users Need To Do Next
Although at this point in time it is unknown if the Android vulnerabilities that have been patched were disclosed by Google’s internal systems or external researchers working with the Android Bug Bounty Program, Samsung has disclosed that a number of its SVEs this month were found by such expert bug bounty hunters. Microsoft has just announced it paid $20 million to such legal hackers for disclosing vulnerabilities across the last year, and Samsung’s Mobile Security Rewards Program is an essential cog in the Galaxy security protection wheel.
Samsung and Google both roll out these security updates over the air automatically, and you will receive a notification if they apply to your device. That’s the good news; less so is that Android is a very fractured ecosystem, especially when compared to Apple’s iOS, where all users get access to the same security updates at the same time. As such, there’s not really a lot you can do but sit tight and wait for the updates to arrive. Google has a support page specifically for information on how to check and update your version of Android.


