Summary
Google has patched CVE-2026-38381, a privilege escalation zero-day vulnerability in the Android kernel that was actively exploited in targeted attacks against Pixel devices before the patch was available. The vulnerability was addressed in Google’s September 2026 Android security update, released September 15, 2026. CVE-2026-38381 is a use-after-free vulnerability in the Android kernel’s memory management subsystem that allows a local attacker with unprivileged application-level access to escalate privileges to the kernel level, achieving full device control. Google noted it is aware of indications the vulnerability may be under limited, targeted exploitation.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 15, 2026 | CVE-2026-38381 exploited in targeted attacks against Pixel devices before patch availability |
| Sep 15, 2026 | Google releases September 2026 Android security update patching CVE-2026-38381 and 36 additional vulnerabilities |
| Sep 17, 2026 | Active exploitation confirmed; zero-day status widely reported |
What Happened
CVE-2026-38381 is a use-after-free vulnerability in the Android kernel. Use-after-free flaws occur when a program continues to reference memory after it has been freed, allowing an attacker to manipulate the freed memory region and redirect program execution. The vulnerability is in a kernel memory management component, meaning successful exploitation achieves kernel-level code execution — the highest privilege level on the device — from an initial position of unprivileged app execution.
The exploitation pattern Google describes as “limited, targeted” is consistent with forensic tool and surveillance software deployment scenarios, where a local privilege escalation zero-day is typically the second stage of a two-stage chain: the first stage gains code execution through a browser or messaging vulnerability, and the second stage escalates those privileges to achieve full device control and persistence. Google has not confirmed this pattern for CVE-2026-38381 specifically.
The September 2026 update patches 37 vulnerabilities in total. CVE-2026-38381 is the only one confirmed exploited in the wild. Pixel devices receive the update over-the-air automatically; users should verify their device is running the September 2026 patch level. Third-party Android manufacturers will receive the patch through Android’s standard disclosure process and are expected to release their own updates on varying schedules.
Note on Domain Intelligence
google.com is the vendor that identified, patched, and disclosed CVE-2026-38381. A domain intelligence score for google.com is not published in this bulletin given the vendor-reporter context. Domain intelligence for google.com is available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026