GrapheneOS Release Notes

Follow

25 release notes curated from 1 source by the Releasebot Team. Last updated: Jul 16, 2026

Get this feed:
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    GrapheneOS logo

    GrapheneOS

    2026071500

    GrapheneOS releases a security preview with Android 17 security patches from July 2026 through January 2027, plus many additional CVE fixes. It also updates Vanadium, improves secure spawning compatibility, and adds kernel and user experience refinements.

    Tags

    Changes since the 2026071100 release:

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026, December 2026 and January 2027 Android Security Bulletins are included in the 2026071501 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026071500

    Secure (exec) spawning: skip vkey.android.vos.VosZygotePreload to make exec-based spawning compatible with apps using V-KEY V-OS Mobile App Protection

    Secure (exec) spawning: skip redundant mount namespace setup for compatibility with anti-tampering code checking Linux mount IDs

    start compat zygote at boot instead of on-demand for compatibility with anti-tampering code checking Linux mount IDs

    use lazy preloading for compat zygote to reduce memory usage when it's not used (it's only used for app processes which disable both hardened_malloc and secure spawning)

    install CarrierConfig2 in all profiles to avoid using default carrier configuration values in secondary users

    notify when Wi-Fi hotspot is disabled due to user change (since users have separate Wi-Fi settings since Android 17) to provide a shortcut for turning it back on via the notification

    remove our change raising the zygote's maximum file limit to 256Ki since this has been implemented upstream as a 512Ki limit with correct handling for 32-bit processes

    kernel (Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold): integrate minor upstream synopsys driver change unrelated to security

    kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.141

    Vanadium: update to version 150.0.7871.124.0

    add secure spawning file descriptor regression test

    Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884, CVE-2026-49918, CVE-2026-49921, CVE-2026-49926, CVE-2026-49927, CVE-2026-49932, CVE-2026-49933, CVE-2026-55256, CVE-2026-55268, CVE-2026-55269, CVE-2026-55273, CVE-2026-55277, CVE-2026-55280, CVE-2026-58823, CVE-2026-58835, CVE-2026-58865

    High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-0053, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49878, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885, CVE-2026-49887, CVE-2026-49895, CVE-2026-49896, CVE-2026-49912, CVE-2026-49913, CVE-2026-49914, CVE-2026-49923, CVE-2026-49924, CVE-2026-49925, CVE-2026-49931, CVE-2026-49934, CVE-2026-49935, CVE-2026-49937, CVE-2026-55257, CVE-2026-55261, CVE-2026-55262, CVE-2026-55263, CVE-2026-55264, CVE-2026-55266, CVE-2026-55270, CVE-2026-55271, CVE-2026-55272, CVE-2026-55278, CVE-2026-55279, CVE-2026-55282, CVE-2026-55286, CVE-2026-55287, CVE-2026-55288, CVE-2026-55289, CVE-2026-55290, CVE-2026-55292, CVE-2026-55294, CVE-2026-58815, CVE-2026-58817, CVE-2026-58821, CVE-2026-58822, CVE-2026-58834, CVE-2026-58836, CVE-2026-58837, CVE-2026-58838, CVE-2026-58841, CVE-2026-58853, CVE-2026-58854, CVE-2026-58856, CVE-2026-58857, CVE-2026-58859, CVE-2026-58860, CVE-2026-58868, CVE-2026-58869

    Unclassified: CVE-2026-28653, CVE-2026-55260, CVE-2026-58820

    Original source
  • Jul 11, 2026
    • Date parsed from source:
      Jul 11, 2026
    • First seen by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026071100

    GrapheneOS ships the 2026071101 security preview with Android 17 July 2026 to January 2027 security patches, a revamped secure exec spawning feature with per-app control, updated kernels and firmware, and fixes for wireless Android Auto, multi-user display, screen recording, and more.

    Tags:

    Changes since the 2026070500 release:

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026, December 2026 and January 2027 Android Security Bulletins are included in the 2026071101 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026071100

    replace secure (exec) spawning feature with a new implementation with improved app compatibility and a per-app toggle replacing the previous global toggle
    extend exec spawning feature to the native zygote added in Android 17
    raise listed security patch level to 2026-07-05 security patch level which has no additional patches listed in either the Android or Pixel bulletin
    update to July 2026 Pixel driver/firmware code
    fix upstream bug in multi-user handling for the WifiService package state listener which among other possible issues was causing wireless Android Auto compatibility issues in secondary users
    fix upstream bug in RemoteException handling for GeocodeProviderBase causing exceptions between the geocoding service and client app to crash the geocoding service
    fix external display mirroring in secondary users (upstream bug)
    fix handling of multiple users for screen recording (upstream bug)
    Sandboxed Google Play compatibility layer: add MODIFY_PHONE_STATE to the special Android Auto phone call permissions toggle since it's needed for managing phone calls in recent versions
    kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.140
    kernel (6.12): update to latest GKI LTS branch revision including update to 6.12.90
    bionic libc: fix API level check for %#m format string (upstream bug)
    update_device.py: improve the experience of testing updates on debug builds by avoiding restarting ADB as root
    PDF Viewer: update to version 32
    Vanadium: update to version 150.0.7871.114.0

    Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884, CVE-2026-49918, CVE-2026-49921, CVE-2026-49926, CVE-2026-49927, CVE-2026-49933

    High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49878, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885, CVE-2026-49887, CVE-2026-49895, CVE-2026-49896, CVE-2026-49912, CVE-2026-49913, CVE-2026-49914, CVE-2026-49923, CVE-2026-49924, CVE-2026-49925, CVE-2026-49931, CVE-2026-49934, CVE-2026-49935, CVE-2026-49937, CVE-2026-55257, CVE-2026-55258, CVE-2026-55261, CVE-2026-55262, CVE-2026-55263

    Unclassified: CVE-2026-28653, CVE-2026-55260

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from GrapheneOS and hundreds of other software products.

    Create account
  • Jul 5, 2026
    • Date parsed from source:
      Jul 5, 2026
    • First seen by Releasebot:
      Jul 7, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026070500

    GrapheneOS releases a sideload-only update that fixes Android 16 QPR2 recovery sideloading so offline updaters can move to Android 17, while also shipping July 2026 to January 2027 security patches and multiple privacy, kernel, Launcher, and Vanadium fixes.

    Users solely doing offline updates via recovery mode sideloading need a to update from Android 16 QPR2 to Android 17. This release fixes upstream bugs for sideloading present in Android 16 QPR2 which prevented updating to Android 17 unless the OS images were far larger than the GrapheneOS ones which triggers a fallback path avoiding the issue.special sideload-only release

    Tags

    Changes since the 2026062800 release:

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026, December 2026 and January 2027 Android Security Bulletins are included in the 2026070501 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026070500

    • rebuild coarse locations from allowlisted fields to resolve an upstream Android privacy flaw leaking secondary fields such as altitude and accuracy to apps without precise location granted
    • System UI:: run scroll capture tile handling on main thread to fix an upstream race condition causing memory corruption
    • Launcher: fix removing space for the quick search bar to avoid removing padding at the bottom
    • fix PIN scrambling for Private Spaces configured to use parent credentials
    • implement enhanced PIN privacy for the new PIN pad used outside of the lockscreen
    • fix handling of TEXT_SHOW_PASSWORD to split TEXT_SHOW_PASSWORD_TOUCH TEXT_SHOW_PASSWORD_PHYSICAL in Android 17
    • backport security patches for FreeType
    • kernel (6.1, 6.6, 6.12): fix upstream double-free bug in USB gadget Ethernet driver which was caught by hardware memory tagging in GrapheneOS
    • kernel (6.1): update to latest GKI LTS branch revision
    • kernel (6.6): update to latest GKI LTS branch revision
    • kernel (6.12): update to latest GKI LTS branch revision
    • kernel (6.1, 6.6, 6.12): backport fixes for CVE-2026-46242
    • enable precompiling dex bytecode for Vanadium now that the Trichrome Library APK no longer breaks compatibility with it (shared library APKs are incompatible with precompilation and this is the only one in the OS)
    • Theme Picker: replace references to apps not included in GrapheneOS to avoid black icons
    • Vanadium: update to version 150.0.7871.63.0
    • Vanadium: update to version 150.0.7871.63.1

    Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884, CVE-2026-49918, CVE-2026-49921, CVE-2026-49926, CVE-2026-49927, CVE-2026-49933

    High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49878, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885, CVE-2026-49887, CVE-2026-49895, CVE-2026-49896, CVE-2026-49912, CVE-2026-49913, CVE-2026-49914, CVE-2026-49923, CVE-2026-49924, CVE-2026-49925, CVE-2026-49931, CVE-2026-49934, CVE-2026-49935, CVE-2026-49937, CVE-2026-55257, CVE-2026-55258, CVE-2026-55261, CVE-2026-55262, CVE-2026-55263

    Unclassified: CVE-2026-28653, CVE-2026-55260

    Original source
  • Jun 28, 2026
    • Date parsed from source:
      Jun 28, 2026
    • First seen by Releasebot:
      Jun 29, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026062800

    GrapheneOS ships a security preview release with Android 17 security patches and broad CVE fixes, while also improving Bluetooth, NFC, Seedvault backups, Sandboxed Google Play compatibility, Vanadium, and Pixel 10 DisplayPort handling.

    Tags

    Changes since the 2026062300 release

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026062801 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026062800

    • add setting for controlling Certificate Transparency (CT) log list downloads used for apps enforcing CT which is enabled by default for apps targeting Android 17+ with a choice between GrapheneOS (default), Standard (previous behavior) and Off

    • enable register_bluetooth_receiver_for_all_users feature flag to fix Bluetooth telecom functionality in secondary users (resolves an upstream regression in Android 17)

    • temporarily use absolute media profile XML paths to work around an exec-based spawning compatibility issue breaking WhatsApp functionality which will be properly addressed by our upcoming overhaul to exec-based spawning

    • add native zygote support to handle Chrome using it and for future use in Vanadium once exec spawning is ported to it

    • build wpa_supplicant_mainline from source since it's used instead of the vendor wpa_supplicant on the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL and Pixel 10 Pro Fold

    • fix NFC quick tile state not updating in secondary users

    • Settings: fix lifecycle of the added NFC state listener to avoid crashes for the Connection preferences page in edge cases

    • Settings: fix minor regression losing listing the duress password feature as being one of the settings available in the screen lock menu which helps people discover the feature

    • Sandboxed Google Play compatibility layer: add stub for PackageInstaller.installPackageArchived()

    • Sandboxed Google Play compatibility layer: use fresh file proxy file descriptors for app opens to fix compatibility issues

    • kernel (Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold): fix another upstream out-of-bounds array read caught by hardware memory tagging in the DisplayPort driver caused by devices implementing the DisplayPort protocol incorrectly and the kernel driver not properly handling the incorrect data

    • don't report harmless ExynosDevice::dynamicRecompositionThreadLoop crash

    • Seedvault: grant local network access to fix local network usage for backups with Android 17

    • Vanadium: update to version 149.0.7827.197.0

    • AppCompatConfig: update to version 7

    • Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884, CVE-2026-49921

    • High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49878, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885, CVE-2026-49887, CVE-2026-49895, CVE-2026-49896, CVE-2026-49912, CVE-2026-49913, CVE-2026-49914, CVE-2026-49924

    • Unclassified: CVE-2026-28653

    Original source
  • Jun 23, 2026
    • Date parsed from source:
      Jun 23, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026062300

    GrapheneOS ships a security preview with Android 17 patches from July through December 2026, plus fixes for an always-on VPN edge case, Bluetooth auto-off for secondary users, and Sandboxed Google Play droidguard and RCS compatibility.

    Tags

    Changes since the 2026062200 release

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026062301 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026062300

    • fix serious upstream Android VPN race condition resulting in the always-on VPN being disabled in edge cases including VPN app updates
    • fix Bluetooth auto-off in secondary users for Android 17
    • Sandboxed Google Play compatibility layer: resolve ThermalManagerService droidguard incompatibility causing RCS to break after droidguard is updated
    • Sandboxed Google Play compatibility layer: increase log level of maybeInterceptBinderProxyDump() to help with debugging droidguard checks

    Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531, CVE-2026-49879, CVE-2026-49882, CVE-2026-49884

    High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28581, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28627, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880, CVE-2026-49881, CVE-2026-49885

    Unclassified: CVE-2026-28653

    Original source
  • Similar to GrapheneOS with recent updates:

  • Jun 22, 2026
    • Date parsed from source:
      Jun 22, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026062200

    GrapheneOS ships a security preview for Android 17 with July through December 2026 patch coverage, a Wi‑Fi quick tile behavior change, recovery mode sideloading fixes, Sandboxed Google Play compatibility updates, Wallpaper Picker photo picker restoration, and Launcher bug fixes.

    Tags

    Changes since the 2026062100 release:

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026062201 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026062200

    • change the behavior of pressing the new Android 17 Wi-Fi quick tile to disabling Wi-Fi instead of only pausing it by disconnecting from the current network and not actively connecting to another automatically

    • backport upstream fix for recovery mode sideloading to replace the workaround we included in our initial public Android 17 release (this will needed to be backported to Android 16 QPR2 to provide a sideload upgrade path)

    • Sandboxed Google Play compatibility layer: add local network access to the permissions added by the wireless Android Auto toggle since it's often required

    • Sandboxed Google Play compatibility layer: add stub for NsdManager.registerService() to handle lack of ACCESS_LOCAL_NETWORK

    • enable photopicker in Wallpaper Picker app to restore photo picker functionality from before Android 17

    • Wallpaper Picker: add vertical padding to the "Choose a photo" button

    • Launcher: fix hidden workspace app labels on non-responsive grids

    • Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531

    • High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880

    • Unclassified: CVE-2026-28653

    Original source
  • Jun 21, 2026
    • Date parsed from source:
      Jun 21, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026062100

    GrapheneOS ships a security preview with Android 17 July to December 2026 patches, broader CVE fixes, and updates for Pixel devices. It also improves compatibility, updates SystemUI and Launcher behavior, and fixes update, Wi-Fi, Widevine, and fingerprint unlock issues.

    Changes since the 2026061800 release

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026062101 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026062100

    • disable MTE for Widevine Rikers service since it's incompatible with it (issue predates Android 17)
    • Sandboxed Google Play compatibility layer: avoid opening extra file descriptions to obtain Play services data prefix paths to avoid a compatibility issue with anti-tampering code used by the Kia Connect app and likely others (issue predates Android 17)
    • separate GrapheneOS framework resource IDs from AOSP resource IDs to avoid incompatibilities with Pixel vendor components (issue predates Android 17)
    • kernel (Pixel 10): fix for an upstream Broadcom Wi-Fi bcm4383 driver memory corruption bug to avoid invalid memory accesses caught by the kernel hardware memory tagging enabled by GrapheneOS
    • disable UBLK feature flag for over-the-air updates due to it likely causing update reliability issues for devices with support for it (6.6 kernel or newer)
    • disable UBLK for generated over-the-air update packages to force disable it for updates from the initial Android 17 release
    • increase the maximum size of log events in production builds to match debug builds to avoid the kernel panic message and traceback being cut off
    • use DevicePolicyManager.MAX_PASSWORD_LENGTH PIN length limit for the new upstream SystemUI PIN user interface for entering the PIN outside of the lockscreen to fix support for the expanded limit of 128 on GrapheneOS instead of using Android's limit of 16 (this didn't apply to passwords and it was straightforward to work around it by changing the PIN to a password)
    • Settings: show night light settings even when Pixel Comfort View is enabled since we're missing the settings for it (currently only relevant to the 10th gen Pixels other than the Pixel 10a)
    • allow using the new flashlight quick tile while locked (GrapheneOS requires unlocking by default for system quick tiles)
    • SystemUI: avoid crashing when trying to edit a screen recording without a video editor app
    • fix upstream bug causing the security scan in the Settings app to take much longer in Android 17 (also impacts the stock OS)
    • fix compatibility issue breaking resetting permissions for apps with special-runtime permissions (Nearby Devices is now split to have Local Network access enabled by default for compatibility for apps not targeting Android 17 and there are bugs with how this is handled)
    • Launcher: remove quick search bar from showing on large display devices since Android 17
    • Launcher: remove space reserved for the quick search bar since Android 17
    • add Pixel Comfort View settings for supported devices (Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold)
    • add back error message for entering an incorrect 2nd factor PIN for the GrapheneOS 2-factor fingerprint unlock feature
    • fix compatibility with the native zygote spawning system added by Android 17 which isn't enabled yet (this was added to provide more lightweight sandboxed renderer processes for Chromium and will benefit Vanadium even more due to having finer-grained process isolation but isn't used by Chromium/Chrome yet and our secure spawning will need to be ported to it)
    • GmsCompatConfig: update to version 171
    • Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531
    • High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880
    • Unclassified: CVE-2026-28653
    Original source
  • Jun 18, 2026
    • Date parsed from source:
      Jun 18, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    • Modified by Releasebot:
      Jul 12, 2026
    GrapheneOS logo

    GrapheneOS

    2026061800

    GrapheneOS releases its initial Android 17 build with July through December 2026 Android security patches, a recovery sideloading workaround, restored Opus sandbox compatibility, Google Play layer updates, and a Vanadium update.

    This is the initial release of GrapheneOS based on Android 17.

    Tags:

    Changes since the 2026061600 release:

    All of the Android 17 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026061801 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026061800

    full 2026-06-05 Pixel security patch level (released with Android 17)

    rebased onto CP2A.260605.016 Android Open Source Project release (Android 17)

    add workaround for upstream bug breaking using recovery mode sideloading for updating to Android 17 releases

    revert in-process Opus codec sandboxed with LFI (Lightweight Fault Isolation) to dedicated sandboxed process in order to restore compatibility with hardware memory tagging and avoid likely holes in LFI

    Sandboxed Google Play compatibility layer: add stubs for BluetoothLeBroadcast methods

    Vanadium: update to version 149.0.7827.159.0

    Critical: CVE-2026-28591, CVE-2026-28604, CVE-2026-28639, CVE-2026-28662, CVE-2026-28666, CVE-2026-45515, CVE-2026-45531

    High: CVE-2025-22442, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-28582, CVE-2026-28584, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28622, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28630, CVE-2026-28631, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28638, CVE-2026-28643, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45523, CVE-2026-45524, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880

    Unclassified: CVE-2026-28653

    Original source
  • Jun 16, 2026
    • Date parsed from source:
      Jun 16, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026061600

    GrapheneOS ships its final Android 16-based release before the initial Android 17 port goes public, bundling July through December 2026 security patches, kernel updates, Vanadium and GmsCompatConfig upgrades, Speech Services updates, and fixes for several key CVEs.

    This is our final release based on Android 16 QPR2/QPR3 since we've completed our initial port to Android 17 and are resolving regressions to prepare it for a public release very soon.

    Tags

    Changes since the 2026060600 release

    All of the Android 16 security patches from the current July 2026, August 2026, September 2026, October 2026, November 2026 and December 2026 Android Security Bulletins are included in the 2026061601 security preview release. List of additional fixed CVEs:
    For detailed information on security preview releases, see our .post about it
    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026061600

    • skip replacing pairip Play Store installer check with Play Store source stamp checks for apps installed directly from the Play Store where the check will pass to avoid causing compatibility issues for apps with deeper pairip integration
    • hardened_malloc: add support for Cuttlefish build targets
    • Network Location: require TLSv1.3 for Apple and Apple China location services in addition to the GrapheneOS service
    • kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.174
    • kernel (6.6): update to latest GKI LTS branch revision
    • kernel (6.12): update to latest GKI LTS branch revision
    • Vanadium: update to version 149.0.7827.102.0
    • Vanadium: update to version 149.0.7827.114.0
    • GmsCompatConfig: update to version 170
    • Speech Services: update to version 3
    • Critical: CVE-2026-27280, CVE-2026-28590, CVE-2026-28591, CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-45515, CVE-2026-45531
    • High: CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-0053, CVE-2026-0054, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0084, CVE-2026-28572, CVE-2026-28582, CVE-2026-28583, CVE-2026-28584, CVE-2026-28585, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28596, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28609, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28631, CVE-2026-28632, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28636, CVE-2026-28638, CVE-2026-28642, CVE-2026-28643, CVE-2026-28644, CVE-2026-28645, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28656, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28664, CVE-2026-28665, CVE-2026-28667, CVE-2026-28668, CVE-2026-28670, CVE-2026-28671, CVE-2026-45513, CVE-2026-45514, CVE-2026-45516, CVE-2026-45517, CVE-2026-45518, CVE-2026-45519, CVE-2026-45520, CVE-2026-45521, CVE-2026-45522, CVE-2026-45523, CVE-2026-45525, CVE-2026-45527, CVE-2026-45528, CVE-2026-45529, CVE-2026-49880
    • Unclassified: CVE-2026-28653
    Original source
  • Jun 6, 2026
    • Date parsed from source:
      Jun 6, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026060600

    GrapheneOS ships a July 2026 security preview with Android 16 security patches through November 2026, plus fixes for the recents button, Settings bugs, Pixel 10a SELinux policy, and updates to Vanadium and AppCompatConfig.

    Tags

    Changes since the 2026060100 release

    All of the Android 16 security patches from the current July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026060601 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026060600

    Launcher: fix upstream bug causing the recents button to become unresponsive for users with third party launchers
    replace validation of Play Store source stamps with a correct implementation (this isn't yet used for security-sensitive purposes but we plan to begin using it to replace security-relevant Play Store source checks in the near future)
    replace implementation of using Play Store source stamps as a substitute for Play Store installer checks included as part of Play Store anti-tampering protection enabled by certain apps (this prevents using the apps when combined with the Play Integrity API store lising toggles)
    Settings: correctly reset tethering offload developer setting when disabling developer options
    Settings: add one-time reset of tethering offload developer setting to re-enable it for everyone who had it disabled by the upstream Android bug when disabling developer options
    Settings: fix upstream null pointer exception bug in SettingsBasePreferenceFragment when listView is null which occurs with at least one of the developer options
    Pixel 10a: add missing SELinux policy for Pixel Camera TPU usage
    Vanadium: update to version 149.0.7827.59.0
    AppCompatConfig: update to version 5
    AppCompatConfig: update to version 6
    Critical: CVE-2026-27280, CVE-2026-28590, CVE-2026-28591, CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662
    High: CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-0053, CVE-2026-0054, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0084, CVE-2026-28572, CVE-2026-28582, CVE-2026-28583, CVE-2026-28584, CVE-2026-28585, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28596, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28609, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28631, CVE-2026-28632, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28636, CVE-2026-28638, CVE-2026-28642, CVE-2026-28643, CVE-2026-28644, CVE-2026-28645, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28656, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28667, CVE-2026-28668, CVE-2026-28670, CVE-2026-28671
    Unclassified: CVE-2026-28653

    Original source
  • Jun 1, 2026
    • Date parsed from source:
      Jun 1, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026060100

    GrapheneOS releases a 2026-06-01 security preview with Android 16 patches from the July through November 2026 bulletins, fixes for location indicators and Pixel kernel bugs, updated core components, and a broad set of critical and high CVE security fixes.

    Tags

    Changes since the 2026052400 release

    All of the Android 16 security patches from the current July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026060101 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026060100

    full 2026-06-01 security patch level

    fix Location access indicator to always properly display when only coarse location is granted too

    kernel (Pixel): fix upstream use-after-free bug in Broadcom Wi-Fi driver caught by hardware memory tagging

    kernel (Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold): fix upstream out-of-bounds array read caught by hardware memory tagging in the DisplayPort driver when using the XReal One Pro (AR glasses) due to the glasses implementing the DisplayPort protocol incorrectly and the kernel driver not properly handling the incorrect data

    kernel (6.1): update to latest GKI LTS branch revision

    kernel (6.6): update to latest GKI LTS branch revision

    kernel (6.12): update to latest GKI LTS branch revision including update to 6.12.89

    Speech Services: update to version 2

    Vanadium: update to version 149.0.7827.48.0

    Auditor: update to version 92

    Critical: CVE-2026-27280, CVE-2026-28590, CVE-2026-28591, CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662

    High: CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2026-0053, CVE-2026-0054, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0084, CVE-2026-28572, CVE-2026-28582, CVE-2026-28583, CVE-2026-28584, CVE-2026-28585, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28596, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28609, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28631, CVE-2026-28632, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28636, CVE-2026-28638, CVE-2026-28642, CVE-2026-28643, CVE-2026-28644, CVE-2026-28645, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28656, CVE-2026-28657, CVE-2026-28658, CVE-2026-28660, CVE-2026-28663, CVE-2026-28667, CVE-2026-28668, CVE-2026-28670, CVE-2026-28671

    Unclassified: CVE-2026-28653

    Original source
  • May 24, 2026
    • Date parsed from source:
      May 24, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026052400

    GrapheneOS ships a security preview with major Android 16 and Pixel patch coverage, plus new GrapheneOS Speech Services, TalkBack set as the default accessibility service, improved network location accuracy, kernel updates, Vanadium browser updates, and several compatibility and bug fixes.

    Changes since the 2026050900 release

    All of the Android 16 security patches from the current June 2026, July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026052401 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026052400

    • add GrapheneOS Speech Services providing a local text-to-speech engine using a model trained by GrapheneOS with fully open source code and training data
    • set GrapheneOS TalkBack as the default accessibility service to support easily enabling it via the accessibility shortcut
    • Network Location: position estimation algorithm overhaul to improve accuracy, reliability and especially the consistency of results along with improving reporting the estimated accuracy
    • Sandboxed Google Play compatibility layer: add stub for NetworkStatsManager.queryDetailsForUidTag()
    • Sandboxed Google Play compatibility layer: stub CarrierConfigManager.getConfigForSubId for Android Auto
    • Keyboard: expand heuristic for working around Jetpack Compose TextField bug
    • remove android.hardware.telephony.satellite feature declaration since it's not supported by GrapheneOS and declaring the feature causes minor issues with recent Android Auto releases
    • Calculator: fix long click to paste not working on first run
    • Seedvault: allow new content provider for DAVx⁵ WebDAV provider (will be replaced with a better backup implementation in the future)
    • kernel (6.1): update to latest GKI LTS branch revision including update to 6.1.173
    • kernel (6.1): update to 6.1.174
    • kernel (6.6): update to latest GKI LTS branch revision including update to 6.6.139
    • kernel (6.6): backport security patches for CVE-2026-46300 and CVE-2026-43503 which aren't exploitable for local privilege escalation from non-root on Android due to not permitting unprivileged use of user namespaces
    • kernel (6.12): update to latest GKI LTS branch revision including update to 6.12.88
    • kernel (Pixel): fix upstream bug in Samsung TEE DMA heap driver used by the PowerVR and Mali GPU drivers for DRM support causing a crash with kernel hardware memory tagging from it freeing a pointer with the tag stripped
    • Vanadium: update to version 148.0.7778.167.0
    • Vanadium: update to version 148.0.7778.178.0
    • Vanadium: update to version 149.0.7827.22.0
    • set the patch level to 2026-05-05 instead of the officially equivalent 2026-05-01 since no patches were listed for 2026-05-05 for either Android or Pixels but not raising it to the equivalent higher value leads to confusion
    • Critical: CVE-2026-0039, CVE-2026-0040, CVE-2026-0041, CVE-2026-0042, CVE-2026-0043, CVE-2026-0044, CVE-2026-0051, CVE-2026-0052, CVE-2026-0080, CVE-2026-0097, CVE-2026-21352, CVE-2026-21353, CVE-2026-27280, CVE-2026-28590, CVE-2026-28591, CVE-2026-28604, CVE-2026-28618, CVE-2026-28639
    • High: CVE-2025-22424, CVE-2025-22426, CVE-2025-48564, CVE-2025-48565, CVE-2025-48566, CVE-2025-48600, CVE-2025-48612, CVE-2026-0008, CVE-2026-0016, CVE-2026-0036, CVE-2026-0048, CVE-2026-0050, CVE-2026-0053, CVE-2026-0054, CVE-2026-0055, CVE-2026-0056, CVE-2026-0059, CVE-2026-0060, CVE-2026-0061, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0067, CVE-2026-0070, CVE-2026-0074, CVE-2026-0076, CVE-2026-0077, CVE-2026-0078, CVE-2026-0079, CVE-2026-0084, CVE-2026-0085, CVE-2026-0086, CVE-2026-0087, CVE-2026-0088, CVE-2026-0089, CVE-2026-0091, CVE-2026-0093, CVE-2026-0094, CVE-2026-0095, CVE-2026-0096, CVE-2026-0098, CVE-2026-0099, CVE-2026-0100, CVE-2026-28572, CVE-2026-28574, CVE-2026-28577, CVE-2026-28578, CVE-2026-28580, CVE-2026-28581, CVE-2026-28582, CVE-2026-28583, CVE-2026-28584, CVE-2026-28585, CVE-2026-28586, CVE-2026-28588, CVE-2026-28593, CVE-2026-28594, CVE-2026-28596, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28606, CVE-2026-28607, CVE-2026-28609, CVE-2026-28612, CVE-2026-28613, CVE-2026-28614, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620, CVE-2026-28623, CVE-2026-28624, CVE-2026-28626, CVE-2026-28631, CVE-2026-28632, CVE-2026-28633, CVE-2026-28634, CVE-2026-28635, CVE-2026-28636, CVE-2026-28638, CVE-2026-28642, CVE-2026-28643, CVE-2026-28644, CVE-2026-28645, CVE-2026-28650, CVE-2026-28652, CVE-2026-28655, CVE-2026-28656, CVE-2026-28658, CVE-2026-28660
    • Unclassified: CVE-2026-0075, CVE-2026-28653
    Original source
  • May 9, 2026
    • Date parsed from source:
      May 9, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026050900

    GrapheneOS ships a security preview with Android 16 patches from the June through November 2026 bulletins, plus kernel fixes for Pixel 8a and Pixel 9a Broadcom Wi‑Fi crashes and system_server stability issues.

    Tags

    Changes since the 2026050700 release

    All of the Android 16 security patches from the current June 2026, July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026050901 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026050900

    kernel (Pixel 8a, Pixel 9a): fix for an upstream Broadcom Wi-Fi bcm4383 driver memory corruption bug to avoid invalid memory accesses caught by the kernel hardware memory tagging enabled by GrapheneOS (the May 2026 Wi-Fi firmware + kernel driver update introduced this issue)

    backport Broadcom Wi-Fi bcm4383 driver changes from CP21.260330.008 (Android 17 Beta 4) to avoid invalid memory accesses (this didn't end up resolving the hardware memory tagging crashes introduced in the May 2026 Pixel update but we kept this to fix additional issues)

    disable buggy upstream IStatusBarNotificationHolder optimization via the upstream feature flag (no_sbnholder) due to it causing occasional system_server crashes from sending overly large Binder transactions

    Critical

    CVE-2026-0039, CVE-2026-0040, CVE-2026-0041, CVE-2026-0042, CVE-2026-0043, CVE-2026-0044, CVE-2026-0051, CVE-2026-0052, CVE-2026-0080, CVE-2026-0097, CVE-2026-21352, CVE-2026-21353, CVE-2026-27280, CVE-2026-28590, CVE-2026-28591, CVE-2026-28604

    High

    CVE-2025-22424, CVE-2025-22426, CVE-2025-48600, CVE-2025-48612, CVE-2026-0008, CVE-2026-0016, CVE-2026-0036, CVE-2026-0048, CVE-2026-0050, CVE-2026-0053, CVE-2026-0054, CVE-2026-0055, CVE-2026-0056, CVE-2026-0059, CVE-2026-0060, CVE-2026-0061, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0067, CVE-2026-0070, CVE-2026-0074, CVE-2026-0075, CVE-2026-0076, CVE-2026-0077, CVE-2026-0078, CVE-2026-0079, CVE-2026-0084, CVE-2026-0085, CVE-2026-0086, CVE-2026-0087, CVE-2026-0088, CVE-2026-0089, CVE-2026-0091, CVE-2026-0093, CVE-2026-0094, CVE-2026-0095, CVE-2026-0096, CVE-2026-0098, CVE-2026-0099, CVE-2026-0100, CVE-2026-28572, CVE-2026-28574, CVE-2026-28577, CVE-2026-28578, CVE-2026-28580, CVE-2026-28581, CVE-2026-28583, CVE-2026-28585, CVE-2026-28586, CVE-2026-28594, CVE-2026-28596, CVE-2026-28599, CVE-2026-28600, CVE-2026-28602, CVE-2026-28603, CVE-2026-28607, CVE-2026-28609, CVE-2026-28612, CVE-2026-28617, CVE-2026-28619, CVE-2026-28620

    Unclassified

    CVE-2026-28618

    Original source
  • May 7, 2026
    • Date parsed from source:
      May 7, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026050700

    GrapheneOS ships a security preview with Android 16 security patches from the June through November 2026 Android Security Bulletins, plus additional CVE fixes and updated Pixel kernel driver sources for May 2026.

    Tags:

    Changes since the 2026050600 release:

    All of the Android 16 security patches from the current June 2026, July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026050701 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026050700

    update Pixel kernel driver sources to May 2026 (this resolves the Pixel 8a and Pixel 9a issues resulting in the release for those being quickly cancelled after early Alpha testing due to the new firmware requiring driver changes)

    Critical: CVE-2026-0039, CVE-2026-0040, CVE-2026-0041, CVE-2026-0042, CVE-2026-0043, CVE-2026-0044, CVE-2026-0051, CVE-2026-0052, CVE-2026-0080, CVE-2026-0097, CVE-2026-21352, CVE-2026-21353, CVE-2026-27280, CVE-2026-28590, CVE-2026-28591

    High: CVE-2025-22424, CVE-2025-22426, CVE-2025-48600, CVE-2025-48612, CVE-2026-0008, CVE-2026-0016, CVE-2026-0036, CVE-2026-0048, CVE-2026-0050, CVE-2026-0053, CVE-2026-0054, CVE-2026-0055, CVE-2026-0056, CVE-2026-0059, CVE-2026-0060, CVE-2026-0061, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0067, CVE-2026-0070, CVE-2026-0074, CVE-2026-0075, CVE-2026-0076, CVE-2026-0077, CVE-2026-0078, CVE-2026-0079, CVE-2026-0084, CVE-2026-0085, CVE-2026-0086, CVE-2026-0087, CVE-2026-0088, CVE-2026-0089, CVE-2026-0091, CVE-2026-0093, CVE-2026-0094, CVE-2026-0095, CVE-2026-0096, CVE-2026-0098, CVE-2026-0099, CVE-2026-0100, CVE-2026-28572, CVE-2026-28574, CVE-2026-28577, CVE-2026-28578, CVE-2026-28580, CVE-2026-28581, CVE-2026-28582, CVE-2026-28583, CVE-2026-28585, CVE-2026-28586, CVE-2026-28588, CVE-2026-28594, CVE-2026-28596, CVE-2026-28602

    Original source
  • May 6, 2026
    • Date parsed from source:
      May 6, 2026
    • First seen by Releasebot:
      Jun 24, 2026
    GrapheneOS logo

    GrapheneOS

    2026050600

    GrapheneOS ships a June 2026 security preview with Android 16 security patches through November 2026, plus Pixel firmware and driver updates, Contact Scopes and IME fixes, bionic compatibility improvements, and many critical and high CVE fixes.

    Tags

    Changes since the 2026050400 release

    All of the Android 16 security patches from the current June 2026, July 2026, August 2026, September 2026, October 2026 and November 2026 Android Security Bulletins are included in the 2026050601 security preview release. List of additional fixed CVEs:

    For detailed information on security preview releases, see our .post about it

    (Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7, Pixel 7 Pro, Pixel 7a, Pixel Tablet, Pixel Fold, Pixel 8, Pixel 8 Pro, Pixel 8a, Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL, Pixel 9 Pro Fold, Pixel 9a, Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL, Pixel 10 Pro Fold, Pixel 10a, emulator, generic, other targets)2026050600

    update Pixel firmware, driver libraries, HALs and other components backported from Android 16 QPR3 from the initial March 2026 release to the May 2026 release (CP1A.260505.005.A1)

    Contact Scopes: add missing handling for QUERY_DEFAULT_ACCOUNT_FOR_NEW_CONTACTS_METHOD was added in Android 16

    backport fix for stuck IME input from May 2026 Pixel update

    bionic: avoid adding an extra guard page below the main thread's pthread_internal_t since it serves no purpose (the stack is in a dedicated mapping from the kernel so the stack guard is immediately below pthread_internal_t) and it causes a crash for incorrect anti-tampering code shared across many banking apps which reads /proc/self/maps to find the main thread's thread-local data including pthread_internal_t based on mapping name and then tries to access the internal libc data stored in an entirely internal libc format without checking if there's a guard page (these anti-tampering checks serve no valid security purpose, cause these apps to break on major Android releases and hinder OS security hardening due to compatibility issues with their incorrect code)

    bionic: remove unnecessary extra naming for mappings to avoid 2 extra system calls for creating a thread

    adevtool: fix update-carrier-settings command

    Critical

    • CVE-2026-0039, CVE-2026-0040, CVE-2026-0041, CVE-2026-0042, CVE-2026-0043, CVE-2026-0044, CVE-2026-0051, CVE-2026-0052, CVE-2026-0080, CVE-2026-0097, CVE-2026-21352, CVE-2026-21353, CVE-2026-27280, CVE-2026-28590, CVE-2026-28591

    High

    • CVE-2025-22424, CVE-2025-22426, CVE-2025-48600, CVE-2025-48612, CVE-2026-0008, CVE-2026-0016, CVE-2026-0036, CVE-2026-0048, CVE-2026-0050, CVE-2026-0053, CVE-2026-0054, CVE-2026-0055, CVE-2026-0056, CVE-2026-0059, CVE-2026-0060, CVE-2026-0061, CVE-2026-0062, CVE-2026-0063, CVE-2026-0065, CVE-2026-0067, CVE-2026-0070, CVE-2026-0074, CVE-2026-0075, CVE-2026-0076, CVE-2026-0077, CVE-2026-0078, CVE-2026-0079, CVE-2026-0084, CVE-2026-0085, CVE-2026-0086, CVE-2026-0087, CVE-2026-0088, CVE-2026-0089, CVE-2026-0091, CVE-2026-0093, CVE-2026-0094, CVE-2026-0095, CVE-2026-0096, CVE-2026-0098, CVE-2026-0099, CVE-2026-0100, CVE-2026-28572, CVE-2026-28574, CVE-2026-28577, CVE-2026-28578, CVE-2026-28580, CVE-2026-28581, CVE-2026-28582, CVE-2026-28583, CVE-2026-28585, CVE-2026-28586, CVE-2026-28588, CVE-2026-28594, CVE-2026-28596, CVE-2026-28602
    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.