Android security updates

Android security updates: check, install and know when support ends

Every month Google publishes a list of Android security flaws, and phone makers ship the fixes in an update. The date shown as Android security update in your Settings tells you how far behind your phone is. This guide shows where to find that date on Pixel and Samsung phones, how to install the update, how long each maker keeps patching, and what to do once the updates stop.

Four steps to check an Android security update: find the patch date in About phone, install updates, update Google Play system, check the support end date
The Android security update date in Settings is the single number that tells you whether your phone has the latest fixes.
Where to look
Settings, About phone, Android version (Software information on Samsung)
Time needed
1 minute to check, 10 to 30 minutes to install and restart
Release rhythm
Google publishes a security bulletin every month; makers follow at their own pace
Support period
7 years on Pixel 8 and later; up to 7 years on many Samsung Galaxy models

What an Android security update contains

An Android security update is a firmware update that closes known holes in the operating system, the Linux kernel and the chip drivers of your phone. It is the main defence against attacks that need no app install at all. Our malware guide covers threats on every platform; this page is only about keeping an Android phone patched.

Your phone gets fixes through three separate channels. Each one has its own date and its own schedule, so it helps to know which is which.

The three ways security fixes reach an Android phone
ChannelWho ships itWhat it fixesWhere you see the date
Android Security BulletinGoogle publishes it, your phone maker ships itAndroid framework, system, kernel and chip vendor componentsAndroid security update (Security patch level on Samsung)
Maker and device bulletinsGoogle for Pixel, Samsung, Motorola and othersFlaws specific to that brand's software, modem or driversSame patch date, listed in the maker's own bulletin
Google Play system updatesGoogle, directly through Google PlayCore modules Google can update without the phone makerGoogle Play system update

The monthly Android Security Bulletin

Google posts the Android Security Bulletin on source.android.com. It is split into Android platform fixes, upstream Linux kernel fixes and fixes from the chip makers (SoC manufacturers) such as Qualcomm, MediaTek and Arm [1]. Google tells its Android partners about every issue at least a month before the bulletin goes public, so makers have time to build their update [2].

Each bulletin has two patch levels. A date ending in 01, such as 2025-12-01, covers the core set of fixes that apply to all Android devices. A date ending in 05 covers everything in that bulletin and all earlier ones, including the kernel and chip fixes [2]. If your phone shows the 05 date for a month, it has the full set.

Maker and chip bulletins

Some fixes are not required to claim a patch level. These appear in the device and partner bulletins: the Pixel Update Bulletin, Samsung's monthly security update page, and those of Motorola and other makers [2]. Samsung says its updates combine Google's Android patches with fixes for Samsung's own software, and that some chip vendor patches can slip to a later month [5].

Google Play system updates

Google Play system updates (Project Mainline) let Google patch some core parts of Android directly, without waiting for the phone maker. Each monthly bulletin says whether any security issue was fixed this way that month [2]. The date appears as Google Play system update on the same screen as your security patch [3]. On many phones it lags a month or two behind; that is normal.

How to check your Android security patch level

The patch level is a date, not a version number. It tells you the most recent bulletin your phone has fully applied.

Pixel and stock Android 14, 15 and 16

  1. Open the Settings app.
  2. Tap About phone (About tablet on a tablet), then Android version [3].
  3. Read three lines: Android version, Android security update and Google Play system update [3]. The second line is your security patch level.

Samsung Galaxy with One UI 6, 7 and 8

  1. Open Settings and scroll to the bottom.
  2. Tap About phone, then Software information.
  3. Find Android security patch level. The Google Play system update date is shown on the same screen.

Motorola, OnePlus, Xiaomi and other phones

Menu names differ by maker, but the date is almost always under About phone. The fastest route on any Android phone is the search bar at the top of Settings. Type security patch and tap the result.

Side-by-side settings paths on a Pixel and a Samsung Galaxy phone for checking the security patch date, installing updates and updating Google Play system
The paths differ between stock Android and Samsung One UI, but each phone shows the patch date in About phone.

How to install an Android security update

Most phones download and install security patches on their own and show a notification when a restart is needed [3]. If you dismissed that notification or the phone was offline, start the update by hand. Connect to Wi-Fi and charge to at least 75% first, because updates can be large [3].

Pixel and stock Android

  1. Open Settings, then System, then Software updates [3]. On some Pixels the item is called Software update [4].
  2. Follow the on-screen steps to download and install.
  3. Restart when asked. Pixels install in the background, and the fix becomes active only after the next restart [3].
  4. For the Google Play system update, open Settings, then Security & privacy, then System & updates, then Google Play system update.

Samsung Galaxy

  1. Open Settings, then Software update.
  2. Tap Download and install. On some carrier models the button reads Check for system updates or Check for software updates [6].
  3. When the download finishes, follow the on-screen steps to install [6]. You can usually install now or schedule it for the night.
  4. For the Google Play system update, open Settings, then Security and privacy, then Updates.

When the update does not show up

  • Updates roll out gradually and can take a few weeks to reach every Pixel, depending on carrier and model [4]. Samsung timing also varies by region, carrier and model [5].
  • If a download fails, Android tries again over the next few days [3]. A "not enough space available" message means you must free storage first [3].
  • Install the newest Android version offered to your phone. Google notes that the latest security update may need the latest Android version for your device [3].

How to read your patch date

Compare the date in Settings with today. A phone on a monthly update plan should rarely be more than two months behind. Samsung puts many budget Galaxy A and M phones on quarterly updates, so a date three or four months old is expected there [5].

Chart of Android security patch age from current to likely unsupported, with what to do at 0 to 2, 3 to 4, 5 to 11 and 12 or more months
A patch date a year old or more usually means the maker has stopped supporting your model.

What "limited, targeted exploitation" means

Most bulletin entries are flaws found by researchers or Google's own teams, with no known attacks. When Google has evidence that attackers already use a flaw, the bulletin says there are indications it may be under limited, targeted exploitation. That wording means real attacks against a small number of chosen people, often with commercial spyware or forensic tools, not a mass campaign.

Limited does not mean harmless. Once a fix ships, attackers can study it and reuse the flaw more widely. Install such an update the day it reaches your phone.

The US Cybersecurity and Infrastructure Security Agency (CISA) adds confirmed cases to its Known Exploited Vulnerabilities catalogue [7]. Our database tracks that catalogue, and it holds over 50 actively exploited flaws in Android, Samsung, Qualcomm, Arm Mali, MediaTek and Google Pixel components. Recent examples:

  • CVE-2026-58704: an authorization bug in the Pixel cellular modem that can let an attacker bypass permission checks. Added in September 2026 and fixed in that month's Pixel update.
  • CVE-2025-48572 and CVE-2025-48633: a privilege escalation and an information leak in the Android Framework, both fixed in the December 2025 bulletin.
  • CVE-2026-21385: memory corruption in many Qualcomm chipsets, listed in the March 2026 Android bulletin.
  • CVE-2025-21042: an out-of-bounds write in Samsung's image codec library that allows remote code execution, fixed in Samsung's April 2025 update.
  • CVE-2025-48543: a use-after-free in Android Runtime that can help an attacker escape the Chrome sandbox, fixed in September 2025.

Note the pattern. Chip and GPU driver flaws from Qualcomm and Arm Mali appear again and again, and they can only be fixed by your phone maker's firmware update. The full list of exploited flaws is on our exploited vulnerabilities page, and the Android entries are also shown below this guide.

How long will your phone get security updates?

Every maker sets its own support period.

Security update periods stated by Google and Samsung
PhonesSupport periodNotes
Pixel 8, 8a, 9, 9a, 10, 10a, 11 and their Pro and Fold models7 years of OS and security updates [4]Counted from the date the phone first went on sale in the US Google Store [4]
Pixel 6, 6a, 6 Pro, 7, 7a, 7 Pro and Pixel Fold5 years of OS and security updates [4]Same start date rule [4]
Pixel 5a and olderNo more updates [4]Replace or limit use
Samsung Galaxy S23 to S26, Z Fold5 to Fold8, Z Flip5 to Flip8, A54 to A57Monthly security updates [5]Samsung extended support to up to 7 years from January 2024 [5]
Samsung Galaxy S22, Z Fold4, Z Flip4, most A, M and F series, Tab S8 to S11Quarterly security updates [5]Models drop off the list when their support period ends [5]
Other Android brandsVaries by maker and carrierGoogle says to contact the maker or carrier [3]

Samsung's lists change as models age, so check the current Samsung security updates scope page for your exact model. If your Galaxy is missing from both the monthly and quarterly lists, it no longer gets regular patches.

Your phone no longer gets updates: what to do

An unsupported phone still works, but every new flaw found in its Android version, kernel or chip stays open for good. You do not have to throw it away today, but change how you use it.

  • Move banking, your main email and your password manager to a supported device. These are what attackers want, and an unpatched phone is the easiest way in.
  • Do not use it as your only two-factor device. If you rely on it for sign-in codes, add a second method such as a hardware key or a supported phone first.
  • Keep apps and Chrome updated through Google Play. App updates still arrive for a while, and the browser is where many attacks start. They do not fix flaws in the system underneath.
  • Install apps only from Google Play and leave Install unknown apps off. Malware that needs a system bug to gain control still has to get onto the phone first.
  • Plan a replacement. When you buy, check the maker's stated update period and how many years of it are left, not just the price.

Some owners install a community-built Android version to keep an old phone patched. These can bring a newer Android release, but they rarely include the closed chip and modem firmware fixes, so many of the exploited flaws listed above stay open. Very cheap unbranded phones can also ship with malware built into the firmware, as in the Triada case, and a phone like that may never get a real fix.

What Play Protect covers, and what it does not

Google Play Protect is on by default on phones with Google Mobile Services. It scans apps and warns about potentially harmful applications, and Google says it matters most if you install apps from outside Google Play [2]. Leave it on: open the Play Store, tap your profile picture, then Play Protect, and check that Scan apps with Play Protect is enabled.

Play Protect does not patch the operating system. A flaw in the kernel, the modem or a GPU driver is fixed only by the firmware update from your phone maker. A phone with Play Protect on and a two-year-old patch date is still exposed to every exploited flaw fixed since then.

Signs your phone may already be compromised

Exploited flaws are mostly used against chosen targets such as journalists, activists, officials and people in legal disputes. If that describes you, or if your phone was unpatched for a long time, look for these signs:

  • Battery drain and heat while the phone is idle, with no app in Battery usage to explain it.
  • Apps in Device admin apps, Accessibility or Notification access that you did not set up.
  • Security settings that switch themselves back, such as Play Protect turning off.
  • Unknown sign-ins on your Google account, or forwarding rules in your email that you did not create.
  • Crashes of messaging apps or the browser right after you receive an unusual message or link.

None of these proves an infection on its own. Our guide on how to check your phone for spyware walks through each check on Android and iPhone, including what to do first if someone close to you may be watching. If you find a malicious app, follow our steps to remove malware from Android. After any infection, secure your accounts from a different, clean device.

Where to go next

Frequently asked questions

How do I check my Android security patch level?

On a Pixel or stock Android phone, open Settings, then About phone, then Android version, and read the Android security update date. On a Samsung Galaxy, open Settings, then About phone, then Software information, and find Android security patch level.

How do I install an Android security update?

On Pixel and stock Android, open Settings, then System, then Software updates. On Samsung, open Settings, then Software update, then Download and install. Connect to Wi-Fi, charge to at least 75 percent and restart when asked, because the fix is active only after the restart.

Is my Android phone still getting updates?

Check the patch date in Settings. If it is more than a year old, your phone has most likely reached the end of support. Then confirm on the maker's page: Google lists support periods for each Pixel and Samsung keeps lists of models on monthly and quarterly updates.

How long do Pixel phones get security updates?

Pixel 8 and later models get 7 years of Android and security updates. Pixel 6, 6a, 7, 7a and Pixel Fold get 5 years. Both periods count from the date the phone first went on sale in the US Google Store. Pixel 5a and older no longer get updates.

How long do Samsung phones get security updates?

Samsung extended security support to up to 7 years for many Galaxy devices from January 2024. Recent flagships such as the S23 to S26 and the newest foldables get monthly updates, while many Galaxy A, M and F phones get quarterly ones. Samsung's security website lists the current models.

What is the difference between the 01 and 05 patch levels?

Each monthly bulletin has two patch levels. The 01 date covers the core fixes that apply to all Android devices. The 05 date covers every fix in that bulletin and earlier ones, including kernel and chip vendor fixes. A phone on the 05 date has the full set.

What is a Google Play system update?

It is a separate update that Google sends through Google Play to patch core parts of Android without waiting for the phone maker. Its date appears next to the security update date in Settings. It is often a month or two behind, which is normal.

Is it safe to keep using a phone that no longer gets updates?

For calls, music or a camera it is usually fine. For banking, your main email or sign-in codes it is not, because new flaws in Android and the chip stay open for good. Move those accounts to a supported device and plan a replacement.

Sources

  1. Android Open Source Project: Android Security and Update Bulletins read 2026-10-09
  2. Android Open Source Project: Android Security Bulletin, December 2025 read 2026-10-09
  3. Android Help: Check and update your Android version read 2026-10-09
  4. Pixel Phone Help: Learn when you'll get software updates on Google Pixel phones read 2026-10-09
  5. Samsung Mobile Security: Security Updates Scope read 2026-10-09
  6. Samsung US Support: How to update your Galaxy phone or tablet read 2026-10-09
  7. CISA: Known Exploited Vulnerabilities Catalog read 2026-10-09

Android flaws exploited in the wild

From CISA's Known Exploited Vulnerabilities catalogue, updated daily: 55 flaws, newest first. Each page says what it means for you and what to do; all of them are in exploited vulnerabilities.

AddedFlawProductRansomware
Sep 16, 2026CVE-2026-58704
Google Pixel Improper Authorization Vulnerability
PixelNot known
Jun 2, 2026CVE-2025-48595
Android Framework Integer Overflow Vulnerability
FrameworkNot known
Mar 3, 2026CVE-2026-21385
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Multiple ChipsetsNot known
Dec 2, 2025CVE-2025-48572
Android Framework Privilege Escalation Vulnerability
FrameworkNot known
Dec 2, 2025CVE-2025-48633
Android Framework Information Disclosure Vulnerability
FrameworkNot known
Nov 10, 2025CVE-2025-21042
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Mobile DevicesNot known
Oct 2, 2025CVE-2025-21043
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Mobile DevicesNot known
Sep 4, 2025CVE-2025-48543
Android Runtime Use-After-Free Vulnerability
RuntimeNot known
Jun 3, 2025CVE-2025-21479
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple ChipsetsNot known
Jun 3, 2025CVE-2025-27038
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple ChipsetsNot known
Jun 3, 2025CVE-2025-21480
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple ChipsetsNot known
Nov 7, 2024CVE-2024-43093
Android Framework Privilege Escalation Vulnerability
FrameworkNot known
Oct 8, 2024CVE-2024-43047
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple ChipsetsNot known
Aug 7, 2024CVE-2024-36971
Android Kernel Remote Code Execution Vulnerability
KernelNot known
Jun 13, 2024CVE-2024-32896
Android Pixel Privilege Escalation Vulnerability
PixelNot known
Jun 12, 2024CVE-2024-4610
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Mali GPU Kernel DriverNot known
Apr 4, 2024CVE-2024-29745
Android Pixel Information Disclosure Vulnerability
PixelNot known
Apr 4, 2024CVE-2024-29748
Android Pixel Privilege Escalation Vulnerability
PixelNot known
Mar 5, 2024CVE-2023-21237
Android Pixel Information Disclosure Vulnerability
PixelNot known
Dec 5, 2023CVE-2023-33107
Qualcomm Multiple Chipsets Integer Overflow Vulnerability
Multiple ChipsetsNot known
Dec 5, 2023CVE-2022-22071
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple ChipsetsNot known
Dec 5, 2023CVE-2023-33106
Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability
Multiple ChipsetsNot known
Dec 5, 2023CVE-2023-33063
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple ChipsetsNot known
Oct 3, 2023CVE-2023-4211
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Mali GPU Kernel DriverNot known
Sep 18, 2023CVE-2022-22265
Samsung Mobile Devices Use-After-Free Vulnerability
Mobile DevicesNot known
Sep 13, 2023CVE-2023-35674
Android Framework Privilege Escalation Vulnerability
FrameworkNot known
Jul 7, 2023CVE-2021-29256
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Jun 29, 2023CVE-2021-25394
Samsung Mobile Devices Race Condition Vulnerability
Mobile DevicesNot known
Jun 29, 2023CVE-2021-25395
Samsung Mobile Devices Race Condition Vulnerability
Mobile DevicesNot known
Jun 29, 2023CVE-2021-25371
Samsung Mobile Devices Unspecified Vulnerability
Mobile DevicesNot known
Jun 29, 2023CVE-2021-25372
Samsung Mobile Devices Improper Boundary Check Vulnerability
Mobile DevicesNot known
Jun 29, 2023CVE-2021-25489
Samsung Mobile Devices Improper Input Validation Vulnerability
Mobile DevicesNot known
Jun 29, 2023CVE-2021-25487
Samsung Mobile Devices Out-of-Bounds Read Vulnerability
Mobile DevicesNot known
May 19, 2023CVE-2023-21492
Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability
Mobile DevicesNot known
Apr 13, 2023CVE-2023-20963
Android Framework Privilege Escalation Vulnerability
FrameworkNot known
Apr 7, 2023CVE-2023-26083
Arm Mali GPU Kernel Driver Information Disclosure Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Mar 30, 2023CVE-2022-22706
Arm Mali GPU Kernel Driver Unspecified Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Mar 30, 2023CVE-2022-38181
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Nov 8, 2022CVE-2021-25369
Samsung Mobile Devices Improper Access Control Vulnerability
Mobile DevicesNot known
Nov 8, 2022CVE-2021-25370
Samsung Mobile Devices Memory Corruption Vulnerability
Mobile DevicesNot known
Nov 8, 2022CVE-2021-25337
Samsung Mobile Devices Improper Access Control Vulnerability
Mobile DevicesNot known
Sep 8, 2022CVE-2011-1823
Android OS Privilege Escalation Vulnerability
Android OSNot known
May 23, 2022CVE-2021-1048
Android Kernel Use-After-Free Vulnerability
KernelNot known
May 23, 2022CVE-2021-0920
Android Kernel Race Condition Vulnerability
KernelNot known
Apr 11, 2022CVE-2021-39793
Google Pixel Out-of-Bounds Write Vulnerability
PixelNot known
Dec 1, 2021CVE-2020-11261
Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon WearablesNot known
Nov 3, 2021CVE-2021-1905
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple ChipsetsNot known
Nov 3, 2021CVE-2019-2215
Android Kernel Use-After-Free Vulnerability
Android KernelNot known
Nov 3, 2021CVE-2020-0069
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Multiple ChipsetsNot known
Nov 3, 2021CVE-2020-16010
Google Chrome for Android UI Heap Buffer Overflow Vulnerability
Chrome for Android UINot known
Nov 3, 2021CVE-2021-27562
Arm Trusted Firmware Out-of-Bounds Write Vulnerability
Trusted FirmwareNot known
Nov 3, 2021CVE-2021-28664
Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Nov 3, 2021CVE-2021-28663
Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Mali Graphics Processing Unit (GPU)Not known
Nov 3, 2021CVE-2020-0041
Android Kernel Out-of-Bounds Write Vulnerability
Android KernelNot known
Nov 3, 2021CVE-2021-1906
Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability
Multiple ChipsetsNot known

Follow the story: Android flaws exploited in the wild

Android, Samsung, Qualcomm, Arm and MediaTek flaws used in attacks, with Android security news. 18 events so far, updated Oct 7, 2026.

See the full timeline →

More from the malware guide

What is malware and how to remove itMalware is any program installed on your device without your informed consent to steal from you, spy on you, lock your files or use your computer for someone else's profit. Viruses, trojans, ransomware, info stealers and remote access tools are all kinds of malware. To remove it, scan with an up-to-date antivirus, run an offline scan, clear what it left behind and then secure your accounts from a clean device.7-Zip and WinRAR vulnerabilities: what was exploited and what to doAttackers have used bugs in 7-Zip and WinRAR to slip malware past Windows warnings or drop files into your Startup folder. Both programs are fine to use, but neither updates itself, so old copies stay open to these attacks for years. Here is what was exploited, how to check your version, and what to do if you already opened a bad archive.Best malware removal tools in 2026Trojans, info stealers, coin miners and rootkits do not all leave through the same door. Some tools block malware before it runs, some scan on demand, some work from outside Windows and some repair what the infection broke. This page matches seven tools we reviewed to those jobs, with prices, free parts and lab results.Chrome zero-day: what it is and how to update Chrome nowA Chrome zero-day is a security flaw that attackers use before Google has shipped a fix. When Google says an exploit exists in the wild, the fix is already out, and your job is to get it running. Open About Google Chrome, let it download the update, click Relaunch and check the version number. It takes two minutes, and the same fix then has to reach Edge, Brave, Opera, Vivaldi and Android WebView.How to remove a virus or malware from an Android phoneAndroid does not get viruses in the old sense. It gets malicious apps: banking trojans that fake your bank's login screen, spyware and stalkerware, SMS stealers and droppers that hide in ordinary-looking apps. They all depend on a few special permissions. Take those away, uninstall the app in Safe mode, then secure your bank and accounts from another device.How to remove a virus or malware from a MacMacs do get malware, and the kind that matters today is not adware but info stealers such as Atomic (AMOS) that empty your Keychain, browser passwords and crypto wallets in minutes. This guide shows how they get in, where they hide on macOS Sonoma 14, Sequoia 15 and later, how to remove them and what to change afterwards.Types of malware: what each kind does and how to spot itMalware is not one thing. A file infector, an info stealer and a browser hijacker behave differently, leave different signs and need different fixes. This guide compares 16 types side by side, then explains each one with current examples and what it looks like on a home computer or phone.Windows zero-day vulnerabilities: what they are and how to close themA Windows zero-day is a flaw that attackers use before Microsoft has a fix. Most of them let malware climb from a normal user account to full control of the PC, and ransomware gangs use them for exactly that. This guide explains how Microsoft ships the fixes, which kinds of flaws get exploited, and how to make sure the fix is really on your PC.
5,454 members already hereReading, writing, commenting and voting. 0 verified · 179 joined this year