Nine critical Android flaws, dozens of high-severity bugs and a batch of Samsung-only fixes that the company won’t fully describe yet. That’s what’s sitting in the Samsung October 2026 security update, and it’s already landing on the newest Galaxy phones. If you own a Galaxy S26 or one of the new foldables, you can likely install it today; everyone else is in the queue.
Here’s the short version. Samsung’s October bulletin, published October 6, lists 45 Google-supplied patches (9 critical, 33 high, 3 moderate), 4 high-severity Samsung Semiconductor fixes and 27 Samsung Vulnerabilities and Exposures (SVEs). Let’s break down what that means for your phone.
| Key fact | Details |
|---|---|
| Official name | SMR Oct-2026 Release 1 |
| Samsung bulletin published | October 6, 2026 (version 1.0) |
| Google patches in Samsung’s bundle | 45 total: 9 critical, 33 high, 3 moderate, 0 low |
| Samsung Semiconductor fixes | 4, all rated high |
| Samsung SVE items | 27 stated, 13 described (6 high, 7 moderate) |
| Android versions covered by Samsung fixes | Android 14 through Android 17 |
| Exploited in the wild? | Google’s bulletin doesn’t flag any October issue as actively exploited |
| First devices | Galaxy S26 series, S26 FE, Z Fold 8, Z Fold 8 Ultra, Z Flip 8 |
What the Samsung October 2026 security update actually fixes
Samsung splits every monthly patch into two buckets: fixes that come from Google’s Android Security Bulletin, and fixes for Samsung’s own software, hardware and services. This month, both buckets are busy.
On the Google side, Samsung’s bulletin lists 45 patches. The nine critical ones include CVE-2026-20519 and CVE-2026-20520, plus a cluster of Android System and Framework bugs. According to TechRepublic, four of the critical System flaws (CVE-2026-55269, CVE-2026-55280, CVE-2026-58835 and CVE-2026-58880) affect Android 16, Android 16 QPR2 and Android 17, and the worst of them allows local privilege escalation with no user interaction. There’s also a critical Framework bug, CVE-2026-58865, that could enable a denial-of-service attack.
What does “local privilege escalation” mean for you? It means an app or attacker that’s already on your phone could grab powers it was never supposed to have. That’s often the second step in a real attack, after something malicious gets installed.
The key takeaway here is simple: none of this is known to be exploited yet, which is exactly why you want to patch before that changes.
The Samsung-only fixes worth knowing about
Samsung’s own SVE list is where things get more specific. Of the 13 items Samsung chose to describe, six are rated high:
- Media extractor: An out-of-bounds write in libsmkvextractor.so could let a local attacker run code.
- WSM service: A use-after-free bug could allow code execution with system privileges. Sammy Fans called this the one to watch most closely.
- Text-to-speech: An out-of-bounds write in Samsung’s TTS library could allow code execution.
- HEIF image decoder: Two input-validation flaws in how cover images and HEIF files are parsed could lead to code execution.
- Locksettings: An attacker who already has root access could reach work or secondary-profile data before you first unlock the phone after a restart.
The moderate items cover a FLAC audio decoder, access-control gaps in CocktailBarService (the Edge panel service) and DownloadProvider, an AI sound-separation library on selected Android 16 and 17 devices, and a permissions bug in CmcCore on Android XR.
Here’s the catch. Samsung’s header says 27 SVEs, but only 13 are spelled out. The bulletin says some items “cannot be disclosed at this time,” which usually means Samsung wants more devices patched before the details go public.
“A patch you can’t read about is still a patch you should install.”
Why Samsung’s count doesn’t match Google’s bulletin
If you go looking at Google’s October 2026 Android Security Bulletin, you’ll notice the numbers don’t line up. Sounds like a mistake, right? Not quite.
Google’s public bulletin, published October 5 and updated October 8, lists 25 CVEs across the Framework and System components, with 7 rated critical and 18 rated high. It says a patch level of 2026-10-01 or later fixes all of them, and its most severe issue is a critical System bug that could lead to local escalation of privilege.
Samsung’s tally of 45 Google patches is bigger because it rolls in additional items that Samsung receives for its devices, such as CVE-2026-20519 and CVE-2026-20520, alongside the 25 public AOSP fixes. Samsung also notes that three CVEs (CVE-2026-28667, CVE-2026-45513 and CVE-2026-57537) already shipped in earlier updates, and one (CVE-2026-57554) doesn’t apply to Galaxy hardware.
| Source | What it counts | Critical | High | Moderate |
|---|---|---|---|---|
| Google Android Security Bulletin | 25 Framework and System CVEs | 7 | 18 | 0 |
| Samsung bulletin, Google patches | 45 patches delivered to Galaxy devices | 9 | 33 | 3 |
| Samsung bulletin, Semiconductor | Exynos and other Samsung chip components | 0 | 4 | 0 |
| Samsung bulletin, SVEs described | Samsung software and services | 0 | 6 | 7 |
And the total? Outlets disagree. Android Headlines and Sammy Fans both headline “up to 83” fixes, while TechRepublic simply cites 9 critical flaws without giving a grand total. You see, depending on whether you count the undisclosed SVEs and the already-patched CVEs, you’ll land somewhere between the high 50s and the low 80s.
The key takeaway here is simple: the exact number matters less than your patch level.
Which Galaxy phones have the October patch so far
Samsung doesn’t publish a device-by-device rollout list. Its bulletin only says the release targets “major flagship models” and that timing varies by region and model. So the table below sticks to devices where a firmware release has been reported by a named outlet.
| Device | Where it’s been spotted | Firmware or build | Reported by |
|---|---|---|---|
| Galaxy S26, S26+, S26 Ultra | Europe from September 29, expanding to India and Thailand | S948BXXS4BZIG (about 550MB, on One UI 9.0) | Sammy Fans |
| Galaxy S26 FE | United States (Verizon), around October 1 | S741USQS2AZI5 | Sammy Fans |
| Galaxy Z Fold 8 Ultra | South Korea first | F976NKSS3AZIJ (5,298.47MB) | eSecurity Planet, citing SamMobile |
| Galaxy Z Fold 8 | South Korea, then Europe and India | Build ending in AZIJ | Sammy Fans, eSecurity Planet |
| Galaxy Z Flip 8 | Reported in the first wave | Reportedly ending in AZIJ | eSecurity Planet |
One interesting wrinkle: Sammy Fans reports the Fold 8 build carries 79 security improvements rather than the full set, because the Samsung Semiconductor fixes don’t apply to its Snapdragon chip. More on that later.
What about older phones? Android Headlines says flagships come first and mid-range models follow. Sammy Fans also spotted the October patch inside a One UI 9 beta build for the Galaxy A55 in India, which is a decent sign the patch is moving down the lineup.
There’s another reason flagship owners shouldn’t get complacent. This week, researchers at Pwn2Own Ireland showed off a successful hack against the Galaxy S26, a reminder that even brand-new phones need every patch they can get. If you’re worried something’s already wrong, here’s how to know if your phone is hacked.
How to install the October update on your Galaxy
The update usually arrives on its own, but you don’t have to wait for the notification. Here’s how to grab it and confirm it worked.
1. Back up anything you can’t lose
Security patches rarely cause trouble, but the Fold 8 Ultra package is over 5GB. Make sure your photos and messages are synced before you start.
2. Plug in and connect to Wi-Fi
A big download over mobile data eats your plan fast. Keep the battery above 50% or leave the phone on its charger.
3. Open the Software update menu
Go to Settings, then Software update, then tap Download and install. Menu wording varies a little by model and software version, as TechRepublic notes.
4. Let the phone restart and finish optimizing
The install includes a reboot. Your phone may feel warm or sluggish for a bit afterward while it optimizes apps. If the heat sticks around, here’s why your phone gets so hot and what to do about it.
5. Check your security software version
Head to Settings, About phone, Software information. You want to see “SMR Oct-2026 Release 1” under Security software version and an Android security patch level of October 1, 2026.
6. Update Samsung Internet separately
TechRepublic flags a separate high-severity Samsung Internet bug, CVE-2026-21132, that could let a remote attacker inject script. It’s fixed in Samsung Internet 30.0.5.24 or later, which comes through the app store, not the system update.
The key takeaway here is simple: a One UI upgrade alone doesn’t prove you have every fix. Always check the patch level itself.
Galaxy phones edging toward the end of support
Not every Galaxy will get this patch on the same schedule. Samsung sorts supported devices into monthly, quarterly and biannual update tiers, and older phones slide down those tiers before dropping off.
Here’s the thing: Samsung doesn’t publish a single official end-of-life list, so the dates below are estimates from tech outlets based on launch dates and Samsung’s policy.
| Device | Status reported | Source |
|---|---|---|
| Galaxy S22, S22+, S22 Ultra | Moved from monthly to quarterly updates in early 2026; security updates expected into 2027 | Android Headlines, ProPakistani |
| Galaxy Z Fold4, Z Flip4 | Last Android version in 2026; security updates expected until 2027 | ProPakistani |
| Galaxy S21 FE 5G, A53 5G | Last Android version in 2026; security updates expected until 2027 | ProPakistani |
| Galaxy Z Fold3, Z Flip3 | Security updates expected to end in 2026 | ProPakistani |
If your phone is on this list, a quarterly-tier device may not see the October fixes until later in the year. It’s the same story Google owners are living through right now with the Pixel 6 end of life.
“Once the patches stop, every new bug becomes permanent.”
What this means if you own a Galaxy tablet
Phones grab the headlines, but Android Headlines says the October patch is expanding to eligible phones and tablets. Samsung’s newest slates, like the Galaxy Tab S12 Ultra, typically follow the flagship phones within weeks.
The same steps apply. Open Software update, install, then confirm the security patch level.
Your next move
The October patch isn’t flashy. There are no new features, no redesigned menus, just a long list of holes closed before anyone gets the chance to use them. That’s exactly the kind of update you shouldn’t put off.
So pick up your Galaxy, open Settings, and check for the update right now. If it’s not there yet, check again in a few days, because Samsung’s rollout is staged by model, region and carrier. And if you’re running an older Galaxy, it’s a good moment to look up how much support your phone has left.
Source: Samsung Mobile Security Bulletin
Frequently Asked Questions
The October 2026 release, labelled SMR Oct-2026 Release 1, bundles 45 Google patches (9 critical, 33 high, 3 moderate), 4 high-severity Samsung Semiconductor fixes and 27 Samsung-specific SVEs. The disclosed Samsung bugs hit components like the WSM service, the HEIF image decoder and the text-to-speech library.
Samsung doesn’t publish one official list, but outlets estimate the Galaxy Z Fold3 and Z Flip3 see security updates end in 2026. The Galaxy S22 series, Z Fold4, Z Flip4, S21 FE and A53 get their last Android version in 2026 but should keep security patches into 2027. Google owners face similar cutoffs, as covered in our Pixel 6 end of life guide.
Open Settings, go to About phone and then Software information. Look for SMR Oct-2026 Release 1 under Security software version and an Android security patch level of October 1, 2026.
Google’s October 2026 Android Security Bulletin doesn’t flag any of its issues as exploited in the wild. That can change quickly once details are public, so installing the update promptly is still the safest move.
Google’s public bulletin covers 25 Framework and System CVEs, with 7 rated critical. Samsung’s bulletin lists 45 Google-supplied patches because it adds extra items delivered for Galaxy devices, such as CVE-2026-20519 and CVE-2026-20520, and it also counts its own Samsung-only fixes separately.
Yes. TechRepublic notes a high-severity Samsung Internet flaw, CVE-2026-21132, that’s fixed in version 30.0.5.24 or later. That update comes through the app store rather than the system software update.

