Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Android Patch Day: 18 Critical Security Vulnerabilities Threaten Current Versions

Google closes 18 critical vulnerabilities in Android 14, 15 and 16. Attackers could gain elevated user privileges or carry out DoS attacks.

Critical Android vulnerabilities discovered

In its latest Android security update, Google has closed 18 critical vulnerabilities affecting Android 14, 15, 16 and 16-qpr2. The security flaws are located in the framework, the kernel and the system, and enable a range of attack scenarios. Users of supported devices should install the available security updates without delay.

Details on the vulnerabilities

System vulnerabilities as the main threat

The majority of the critical vulnerabilities affect the Android system. Particularly problematic is CVE-2026-0043, which allows attackers to obtain elevated user privileges by means that have not been described in detail. A further system vulnerability (CVE-2026-64505) enables DoS attacks that can lead to system crashes.

Framework and kernel affected

The Android framework also contains critical security flaws, including CVE-2025-65018 and CVE-2025-64720, which offer similar attack options. In the kernel, the vulnerability CVE-2025-40214, rated "high", was identified; it too can serve attackers as a stepping stone for obtaining elevated user privileges.

Additional components vulnerable

Alongside Android's own components, parts supplied by hardware manufacturers are also affected. Components from Imagination Technologies, MediaTek, Qualcomm and Unisoc contain security flaws. The remaining vulnerabilities are largely rated "high" and can lead to information leaks.

Assessing the threat situation

No active attacks known

To date, Google has no indication that attackers are already actively exploiting the identified vulnerabilities. However, this does not mean the threat should be neglected, since the critical rating of the flaws points to a high damage potential.

Changed update strategy

Since July 2025, Google has changed its update strategy and now closes only particularly dangerous vulnerabilities on a monthly basis. Further updates are distributed quarterly. With its large number of closed vulnerabilities, the current patch cycle shows considerably more activity than May, in which only a single security flaw was fixed.

Practical recommendations for users

Install updates immediately

Users of Android devices should not hesitate and should install the available security updates with patch levels 2026-06-01 or 2026-06-05 without delay. This applies in particular to devices that are still within their official support period.

Watch for manufacturer updates

Besides Google, various manufacturers such as Honor, Samsung, Motorola, Nokia, Oppo, Sony, OnePlus and Fairphone provide monthly security patches for selected smartphone models. Users should check regularly whether updates are available for their specific devices.

Take device age into account

A critical aspect of Android security lies in the differing update support offered by manufacturers. While Google Pixel devices receive updates promptly, devices from other manufacturers often get security patches considerably later or, in the worst case, not at all. When choosing a device, the manufacturer's update policy should therefore be taken into account.

Outlook and consequences

Long-term security strategy

The current situation demonstrates the importance of a proactive security strategy for mobile devices. Companies and private users alike should pay particular attention to the availability of regular security updates when deploying Android devices.

Relevance for security managers

For security managers in companies, this case underlines the need for a structured mobile device management strategy. The prompt distribution of security updates should be anchored in every IT security strategy in order to minimise potential attack surfaces.

The sheer number of critical vulnerabilities makes it clear that Android devices require continuous attention when it comes to security updates. Only through consistent update cycles can users protect their devices against the identified threats.