Samsung has announced its October 2026 security update for Galaxy devices, which addresses 76 vulnerabilities across core Android, Samsung components, and its proprietary software. The update is being rolled out to eligible devices and will reach more models over the coming days.

Read More

The October security package includes 45 fixes sourced from the Android Security Bulletin, encompassing 9 critical vulnerabilities, 33 high-severity issues, and 3 moderate problems. Additionally, Samsung has resolved 4 high-severity vulnerabilities in its Semiconductor components.

Among the significant vulnerabilities, several could enable local attackers to execute arbitrary code. Notable issues include out-of-bounds write flaws in libsmkvextractor.so and libsamsungtts.so, a use-after-free vulnerability in the WSM service, and input validation issues within the HEIF image handling component. Furthermore, a flaw in Locksettings may allow a local attacker with root access to retrieve data from a tied profile before the device is first unlocked.

The update also addresses moderate-severity out-of-bounds memory flaws in media components and access control issues in CocktailBarService and DownloadProvider that could expose sensitive information. An additional issue in CmcCore could permit local attackers to utilize privileged APIs without proper authorization.

Samsung is initially rolling out the security update to the Galaxy S26 series and Z8 foldable devices. Users can check for the update by navigating to Settings > Software update > Download and install. The company may release the latest patch as a standalone update or include it in the One UI 9 rollout.

This update reflects Samsung's ongoing commitment to improving the security of its devices.