Android Security Bulletins have been twisted into a way to mislead the public about security. Patches are only listed in the bulletins 2-6 months after they're disclosed to each Android OEM and allowed to be shipped. Patches listed in the September 2026 bulletin were available to ship for months.
Android Security Bulletins are divided into two sections. The first section contains High and Critical severity Android Open Source Project (AOSP) patches backported to older releases. For years already, Low and Moderate severity AOSP patches have required updating to the latest major releases.
The first section is the main portion of the patches and gets provided 2-6 months in advance as security preview patches. The security preview patches are allowed to be shipped right away, which is sensible. The horrific part is delaying disclosure of the vulnerabilities and patches for months.
The security preview patches aren't only for Android projects but rather also include patches to external projects. Some of these external patches are already publicly disclosed while others are not. As one example, there have been non-publicly-disclosed security preview patches for wpa_supplicant.
GrapheneOS provides security preview releases providing early access to all of the security preview patches. It's the only OS quickly shipping all of these patches. A subset of these patches are shipped early by the stock OS on Pixels and Samsung flagships but far from all and it comes weeks later.
In 2026, Google has been completely overwhelmed by the volume of vulnerabilities being discovered by AI models both internally and externally. They recently announced to OEMs that the full set of High and Critical severity patches will only be available through the latest yearly and QPR2 releases.
Their announcement explains the massive number of vulnerabilities discovered by AI models internally will only be patched in the latest major releases. A subset deemed to pose an imminent risk to users will be backported to the most recent releases but not to older releases with security support.
Each Android Security Bulletin also has a 2nd section with listing an extraordinarily small subset of the vulnerabilities patched in the upstream Linux kernel along with a small subset of vulnerabilities patched in drivers/firmware shared by many devices. This is deliberate to keep the bar very low.
Google wants Android users to feel safe due to believing they have the latest privacy and security patches. Therefore, they delay patches being listed in the bulletins for months and don't list a substantial portion of Linux, driver and firmware patches. It's a very low bar so devices can keep up.