India’s cybersecurity agency CERT In has issued a security warning about multiple vulnerabilities affecting several versions of the Android operating system. The advisory covers Android 14, Android 15, Android 16, Android 16 QPR2 and Android 17, making the warning relevant to a wide range of smartphone and other Android device users.
CERT In published Vulnerability Note CIVN 2026 0491 on October 6, 2026. The agency has classified the overall risk as high because some of the reported vulnerabilities could allow attackers to gain elevated privileges, access sensitive information, execute arbitrary code or cause denial of service conditions. The advisory is aimed at both individual users and organisations using affected Android devices.
The vulnerabilities are associated with weaknesses in different parts of the Android operating system. CERT In specifically identifies issues involving Android Framework, System and Google Play system components. These components perform important functions on Android devices, meaning security weaknesses in them can potentially have a significant impact if exploited.
One of the major concerns highlighted in the advisory is privilege escalation. A successful exploitation of such a vulnerability could allow an attacker to obtain permissions beyond those normally available to an application or user. Depending on the specific vulnerability and the device configuration, this could increase the potential impact of an attack.
The advisory also mentions the possibility of sensitive information disclosure. Modern smartphones contain a large amount of personal and important information, including contacts, messages, photographs, documents, account information and application data. A vulnerability that enables unauthorised access to information can therefore create privacy and security risks.
Some vulnerabilities may also allow arbitrary code execution. This means an attacker could potentially cause a vulnerable device to perform unauthorised actions. The actual impact depends on the vulnerability, device software, available security protections and whether exploitation is successful. CERT In has therefore advised affected users and organisations to take appropriate security measures.
Google’s October 2026 Android Security Bulletin provides additional details about vulnerabilities addressed through the latest Android security updates. The bulletin, published on October 5, states that Android security patch levels dated October 1, 2026 or later address the issues covered by the update.
Google’s bulletin lists vulnerabilities across Android components, including Framework, System and other platform areas. Several vulnerabilities affecting Android 14, 15, 16, 16 QPR2 and 17 are classified as high severity. The bulletin also lists critical vulnerabilities affecting some of the newer Android versions.
Among the issues listed by Google is a critical vulnerability in the System component that could potentially allow local privilege escalation without requiring additional execution privileges. Google states that user interaction is not required for exploitation of the affected issue. The company also lists other critical and high severity vulnerabilities involving denial of service, privilege escalation, remote code execution and information disclosure.
The presence of a vulnerability in a security bulletin does not automatically mean that every affected Android smartphone has been compromised. Security bulletins identify weaknesses that need to be addressed through software updates. Whether a particular device is vulnerable also depends on its manufacturer, software build, security patch level and the updates already installed.
Android users should therefore check the security patch information on their smartphones. The exact steps can differ between manufacturers, but users can generally find software update and security information under the Settings application. If a newer security update is available, installing it is one of the most important steps users can take to reduce exposure to known vulnerabilities.
Users should also avoid installing applications from untrusted sources. Downloading apps only through reputable sources, reviewing application permissions and keeping important applications updated can provide additional protection. Suspicious links, unexpected attachments and unknown applications should also be treated carefully.
For businesses and organisations using Android devices, the issue can require additional attention. Organisations should review the devices and Android versions in use, verify their security patch levels and apply vendor supplied updates according to their internal security procedures. Devices that cannot receive current security patches may require additional risk controls or replacement, depending on the organisation’s security requirements.
It is also important for users to understand that Android version numbers alone do not determine whether a device has received the relevant security fixes. Manufacturers distribute updates according to their own software release schedules. Therefore, two smartphones running the same Android version can have different security patch levels.
The latest CERT In warning is part of the agency’s continuing role in monitoring and reporting cybersecurity vulnerabilities. CERT In is India’s national agency responsible for responding to computer security incidents and issuing vulnerability notes, alerts and other cybersecurity guidance.
For Android users, the most practical step is to check the device’s current security patch level and install any available update from the smartphone manufacturer. Users should not assume that having a newer Android version automatically means that every security vulnerability has been addressed.
The October 2026 Android security bulletin also highlights why regular software updates remain important. Security updates can contain fixes for vulnerabilities that may otherwise expose devices to different forms of attack. Google recommends using an Android security patch level of October 1, 2026 or later to address the vulnerabilities covered by its October bulletin.
The CERT In warning does not establish that millions of Android phones in India have already been hacked. Instead, it identifies vulnerabilities that could create security risks for affected devices if they remain unpatched and are successfully exploited. Users should therefore treat the warning as a reason to review their device security rather than as confirmation that their personal data has been compromised.
Android users who regularly install security updates, keep applications updated and avoid suspicious downloads can reduce their exposure to known threats. Checking the security patch date is particularly important because manufacturers may release security fixes separately from major Android version upgrades.
The warning covers Android 14 through Android 17, along with Android 16 QPR2, and therefore applies to a broad range of devices. However, the exact availability of a security update depends on the smartphone manufacturer and model. Users should follow official update notifications and the support information provided by their device manufacturer.





