Android security

AppWizard
September 18, 2026
Google's September 2026 Pixel Update Bulletin includes patches that affect standard Android platform code, relevant to both Pixel and non-Pixel devices, which have not been included in the regular monthly Android Security Bulletin. GrapheneOS has noted that Android 17 QPR1 introduced new developer APIs not present in the Android Open Source Project (AOSP) for the first time since Android Honeycomb, with one new package and modifications to sixteen others. GrapheneOS is backporting Pixel firmware and drivers from QPR1 onto Android 17 but lacks permissions to distribute this work. Additionally, there has been a delay in Google’s compliance with a GPL source request, with access granted over two weeks after the initial request. Starting in 2027, Google will require all Android app developers to register with them and provide legal identification and signing key evidence, complicating the process of sideloading unverified apps. GrapheneOS and other organizations are advocating for the Keep Android Open campaign against these developments, which may restrict competition and tighten Google's control over the Android ecosystem.
AppWizard
September 18, 2026
The new AndroidX Security State libraries, with stable releases of Security State v1.1.0 and Security State Provider v1.0.0, allow developers to evaluate the security status of individual device components. They provide three levels of security patch information: Device Security Patch Level (DSPL), Published Security Patch Level (PSPL), and Available Security Patch Level (ASPL). These libraries enable checks on critical components of the Android operating system, including system modules and the Linux kernel, which are represented by version numbers rather than monthly patch dates. Applications that prioritize security can utilize this detailed patch information to assess vulnerabilities, particularly those tracked as Common Vulnerabilities and Exposures (CVEs). The libraries also integrate with the Open Source Vulnerabilities (OSV) database for access to Android Security Bulletin data and device-specific vulnerability reports. Additionally, Android 17 allows manufacturers to declare individual security fixes beyond the stated security patch level, and Google is working with manufacturers to transition their OTA update clients to this new standardized system.
AppWizard
September 17, 2026
On September 15, 2026, Google released the beta OS update "Android 17 QPR2 Beta 5" for Google Pixel devices in the Android Beta Program. This update includes support for new Pixel devices: "Pixel 11," "Pixel 11 Pro," "Pixel 11 Pro XL," and "Pixel 11 Pro Fold," while excluding "Pixel 6" and "Pixel 6 Pro." The update is distributed via Over-the-Air (OTA) to 23 models, including "Pixel 6a," "Pixel 7," and "Pixel 8 Pro." Key features include "Call Forwarding Hardening," which restricts access to call-forwarding USSD codes to enhance security against scams. The update also includes eight bug fixes, addressing issues with Bluetooth device type display, unexpected reboots, volume slider UI, text rendering, Private Space unlocking, HDR mode, Camera app crashes, and Bluetooth audio distortion. The build number changes to "CP41.260828.004.A8" or "CP41.260828.005.A6," with the Android security patch level updated to "August 5, 2026," and "Google Play services" upgraded to version 26.28.33 or later.
AppWizard
September 10, 2026
On September 9, 2026, Google rolled out the “Google Play System Update” for Android devices, which is part of the monthly “Google System Updates” aimed at enhancing security and reliability. The update reflects an “Update date: September 1, 2026,” and includes improvements to the app version of “Mainline services,” updated to version v2026-09-01S+. Users can check for the update in device settings under [Security & privacy] → [System & updates] → [Google Play system update], or through the “Mainline services” app, available since November 19, 2025.
AppWizard
September 7, 2026
The GrapheneOS team is working on a new OS release to fix a volume bar UI regression caused by an upstream Android security preview patch and a UI issue within the Private Space feature. The release of the revamped Messages app has been delayed to follow the upcoming OS release, and there is currently no timeline for the integration of RCS (Rich Communication Services) into the new Messages app. The team is focused on enhancing user privacy and functionality while developing applications and privacy controls to reduce Google's influence.
AppWizard
September 4, 2026
The Indian Cyber Crime Coordination Centre (I4C) has issued an advisory about malicious Android applications disguised as adult-content apps, which are promoted through social media and distributed outside official app stores. The National Cybercrime Threat Analytics Unit (NCTAU) warned that these apps can compromise mobile device security by requesting sensitive permissions and may install additional software without user consent, leading to unauthorized financial transactions. Users are advised to download apps only from trusted sources like the Google Play Store, avoid installing APK files from unverified sources, and refrain from granting accessibility permissions to untrusted applications. Recommendations include regularly reviewing installed apps, keeping Google Play Protect enabled, and monitoring bank accounts for unauthorized activities. Victims of cyber fraud are encouraged to report incidents via the national cybercrime helpline or the government’s reporting portal.
AppWizard
September 1, 2026
Cybercriminals are targeting Android users with deceptive advertisements for malicious applications disguised as pornographic content on platforms like Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU) has reported that these ads lead users to phishing traps or malware downloads that can compromise banking credentials. Malicious applications linked to this threat include “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa.” The scam involves promoting these apps through enticing ads, redirecting users to websites offering pornographic content, and prompting them to download APK files directly from these sites, often using “.live” domains. The initial app may request users to download a second package disguised as an update, which can exploit permissions granted to the first app. This malware can gain extensive control over the device, potentially installing a VPN that routes internet traffic through attackers' servers. To protect against this threat, users should download apps only from trusted sources, avoid installing APK files from ads or suspicious links, refrain from granting Accessibility access to unknown apps, regularly review installed apps, keep Google Play Protect enabled, and monitor bank accounts for unusual activity. If a suspicious app cannot be uninstalled, users can try Safe Mode, remove special permissions, or perform a factory reset as a last resort.
AppWizard
August 29, 2026
Google has introduced several network security enhancements in Android 17 to improve user privacy. One key feature is Encrypted Client Hello (ECH), which encrypts domain names to prevent external observers from monitoring user activities. ECH is integrated with private DNS and is enabled by default for apps using compatible networking libraries. Google claims to be the first major mobile operating system to implement widespread ECH support. Testing conducted by Jigsaw showed stable connection success rates and minimal interference across various networks. Additional security features in Android 17 include: - Local Network Protection, requiring apps to request permission before accessing devices on a user's home network. - Certificate Transparency, mandating public logging of certificates to detect forged ones. - A 2G Network Shutdown option for mobile operators to disable 2G services, reducing exposure to phishing messages.
Search