Samsung opened August by getting ahead of Google — again. The company has published full details of its August 2026 Security Maintenance Release (SMR), a patch addressing 56 total vulnerabilities across Galaxy phones and tablets running Android 14, 15, and 16. As has become routine, Samsung detailed the fixes before Google’s own official Android Security Bulletin breakdown.
Here’s what’s actually in it, what’s most serious, and when you’ll get it.

The breakdown: 38 from Google, 18 from Samsung
The patch splits into two buckets:
- 38 Android security fixes pulled from Google’s August Security Bulletin — of these, 8 are rated critical and 30 rated high priority.
- 18 Samsung-specific fixes covering One UI and Galaxy’s own apps — 2 high priority, 14 moderate, and 2 with undisclosed severity.
Worth noting: nine vulnerabilities Google listed in its bulletin didn’t make it into Samsung’s release this month. One had already been patched back in Samsung’s July update; the other eight simply don’t apply to Samsung’s devices.
The vulnerabilities worth actually knowing about
A few of the named issues stand out beyond the raw count:
- Clipboard exposure (SVE-2026-0916): An authorization bypass in SemClipboardService previously let unprivileged local apps scrape clipboard data — a meaningful privacy gap, since clipboards routinely hold passwords, one-time codes, and other sensitive text people copy and paste without thinking twice.
- Weaver lockout bug (SVE-2026-1829 / CVE-2026-21064): Incorrect access control in the Weaver hardware module could let a local attacker render a device completely inoperable.
- Galaxy Themes exploit (SVE-2026-1946 / CVE-2026-21073): Insufficient input validation that could allow a physical attacker with hands-on device access to launch arbitrary activities.
- App Lock bypass: A flaw that could let someone with physical access to the device get around App Lock protections entirely.
- Media codec flaws: Out-of-bounds write vulnerabilities affecting VC1 and MPEG4 codec libraries — the kind of low-level memory bug that’s historically been a favorite target for local exploitation through malformed media files.
- Samsung Messages exposure: A separate fix addressing a way physical attackers could access sensitive information through the Messages app.
Most of these fall into the “local” or “physical attacker” category rather than remote exploits — meaning the realistic risk is largely tied to someone having direct access to an unlocked or compromised device, not a random attacker reaching in over the internet. That doesn’t make them trivial, but it does shape who should be most concerned: primarily people whose devices could plausibly fall into the wrong hands, rather than every Galaxy owner facing a remote hacking risk.
When you’ll actually get it
Samsung’s rollout follows its usual staggered pattern, starting with its newest hardware and working down the lineup:
- Galaxy Z Fold 8 and Galaxy Z Flip 8 — the newest foldables, first in line.
- Galaxy S26 series, followed by the Galaxy Z Fold 7 and Galaxy Z Flip 7.
- Older flagships and more budget-friendly Galaxy devices follow after that.
The update is expected to begin rolling out within days of the announcement, though full global availability — as always with Samsung’s monthly patches — will take longer to reach every eligible device.
How to check for it
Once it’s live for your device: Settings > Software Update > Download and Install.
The bigger pattern here
Samsung beating Google to the punch on patch details isn’t new — it’s been the norm for a while now, and it’s a small but real signal about how seriously Samsung treats its own security disclosure cadence separate from Google’s. For Galaxy owners, the practical takeaway is simple and hasn’t changed in years: security patches like this one are free, low-effort, and close real gaps — eight critical-rated vulnerabilities is not a number worth sitting on. If your phone shows the update available, it’s worth installing sooner rather than later.
