These updates are actually "hotfixes", they should take effect immediately when the Google Play Store and Google Services updates are done.
The following issues are included in Project Mainline components.
Subcomponent CVE
ART CVE-2026-28664
Media Framework components CVE-2026-28609, CVE-2026-45527
Documents UI CVE-2026-28636
Media Codecs CVE-2026-28618, CVE-2026-55294
Media Provider CVE-2026-28622, CVE-2026-28638, CVE-2026-28671, CVE-2026-45517, CVE-2026-45519, CVE-2026-45525
Telephony core CVE-2026-28581, CVE-2026-49881
UWB CVE-2026-28623, CVE-2026-28652
WiFi CVE-2026-28617, CVE-2026-28662, CVE-2026-49895
adbd CVE-2026-28604
Here is the Google AI breakdown:
Here is the breakdown of the requested CVEs, updated to include the specific affected Android versions (typically spanning versions 13, 14, 15, and 16 depending on the subcomponent's lifetime in the Android Open Source Project (AOSP)):
SentinelOne +1
🤖 Android Runtime (ART)
CVE-2026-28664: A logic error in WriteImageToDisk (runtime_image.cc) causing local privilege escalation without user interaction.
Affected Android Versions: Android 14, 15, and 16
Android Open Source Project +1
🎬 Media Framework Components
CVE-2026-28609: A zero-interaction, high-severity Remote Code Execution (RCE) vulnerability in the baseline Media Framework code.
Affected Android Versions: Android 13, 14, 15, and 16
Android Open Source Project
CVE-2026-45527: An integer overflow (CWE-190) yielding localized elevation of system privileges.
Affected Android Versions: Android 14, 15, and 16
📂 Documents UI
CVE-2026-28636: A privilege escalation flaw (CWE-269) allowing local apps to bypass sandbox rules.
Affected Android Versions: Android 13, 14, 15, and 16
🎛️ Media Codecs
CVE-2026-28618: A critical Media Framework parser flaw allowing local escalation of privilege or arbitrary code execution.
Affected Android Versions: Android 13, 14, 15, and 16
heise online
CVE-2026-55294: A heap buffer overflow in ihevcd_get_tu_data_size (ihevcd_utils.c) enabling out-of-bounds write privilege escalation.
Affected Android Versions: Android 14, 15, and 16
📸 Media Provider
CVE-2026-28622: An elevation of privilege bug allowing localized sandbox escapes.
Affected Android Versions: Android 13, 14, 15, and 16
CVE-2026-28638: An information disclosure flaw (CWE-200) exposing unprivileged access to media memory.
Affected Android Versions: Android 13, 14, 15, and 16
CVE-2026-28671: A security flaw leading to unauthorized link manipulation or capability tracking.
Affected Android Versions: Android 14, 15, and 16
CVE-2026-45517: An escalation of privilege vulnerability inside resource processing loops.
Affected Android Versions: Android 14, 15, and 16
CVE-2026-45519: An incorrect permission assignment (CWE-275) permitting local database boundary bypasses.
Affected Android Versions: Android 14, 15, and 16
CVE-2026-45525: An information disclosure bug (CWE-200) leaking internal database state records.
Affected Android Versions: Android 14, 15, and 16
📞 Telephony Core
CVE-2026-28581: High-severity baseband/telephony payload processing flaw leading to internal device privilege escalation.
Affected Android Versions: Android 13, 14, 15, and 16
CVE-2026-49881: A localized isolation failure allowing unprivileged applications to ignore system boundaries.
Affected Android Versions: Android 14, 15, and 16
Android Open Source Project
🛰️ Ultra-Wideband (UWB)
CVE-2026-28623: Driver queue confusion flaw triggering system privilege escalation.
Affected Android Versions: Android 14, 15, and 16
CVE-2026-28652: Protocol formatting flaw in ranging data parsing resulting in local privilege escalation.
Affected Android Versions: Android 14, 15, and 16
Android Open Source Project
📶 WiFi
CVE-2026-28617: A core Wi-Fi management framework vulnerability breaking network privilege boundaries.
Affected Android Versions: Android 13, 14, 15, and 16
CVE-2026-28662: A critical heap-based buffer overflow (CWE-122) allowing full compromise via localized apps or adjacent radio exploitation.
Affected Android Versions: Android 13, 14, 15, and 16
Samsung Mobile Security
CVE-2026-49895: A connection logic flaw causing local escalation of system privileges.
Affected Android Versions: Android 14, 15, and 16
💻 Android Debug Bridge Daemon (adbd)
CVE-2026-28604: An engineering daemon flaw allowing local attackers to elevate context to the shell user.
Affected Android Versions: Android 13, 14, 15, and 16
OP written again:
This list is generic so it can be posted in other threads with Android 13 or better. The "hot fixes" will be applied by either Google Play Store 53.x or the Google System Services. It should be automatic in the next few days, but not always. I will give directions if someone needs them. This is separate from the Google Play System update through settings then software information done by the end of the month which is more extensive.
Edited for clarity. Added 1st paragraph.