Description:
Google has released Android Security Bulletin (Android 17 Security Release Notes) to fix multiple security vulnerabilities in Android operation system. The list of security updates can be found at:
https://source.android.com/docs/security/bulletin/android-17
Affected Systems:
- Android 17 devices with a security patch level prior to 2026-07-01
Impact:
Successful exploitation of the vulnerabilities could lead to remote code execution, denial of service, elevation of privilege or information disclosure on an affected system.
Recommendation:
Some manufacturers have fixed or have planned to fix the vulnerabilities in their Android systems. Users are recommended to consult the product vendors to confirm the availability of patches. If patches are available, users should upgrade to the fixed versions or follow the recommendations provided by the product vendors to mitigate the risk.
More Information:
- https://source.android.com/docs/security/bulletin/android-17
- https://www.hkcert.org/security-bulletin/android-multiple-vulnerabilities_20260622
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25836 (to CVE-2022-25837)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40108
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40132
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48571
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48617
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48640
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48643
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0019
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0057
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0063 (to CVE-2026-0064)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0068
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0071
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0081 (to CVE-2026-0083)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0092
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28575 (to CVE-2026-28576)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28587
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-28615