Android
Skip to content

Android / News

Samsung August Security Update: 8 Critical Fixes, and a Number That Does Not Add Up

Source: Unsplash

Samsung has published its August security update, and the fixes are worth installing today rather than whenever your phone gets round to asking. The release covers eight vulnerabilities Google rates Critical and thirty rated High, plus a set of Samsung’s own patches for One UI and Galaxy hardware. To check whether you have it, open Settings, then Software update, then Download and install. The line you want to see afterwards is a security patch level of 1 August 2026 or later.

What the bulletin actually contains

Samsung publishes its monthly Security Maintenance Release as a bulletin listing every fix by identifier. We counted the August entries directly from Samsung’s own security page rather than relying on the summaries circulating this week.

Category Count Source
Critical 8 Google, via the Android Security Bulletin
High 30 Google, via the Android Security Bulletin
Moderate None listed Google
Samsung SVE items 16 Samsung, One UI and Galaxy specific

That comes to 38 fixes inherited from Google and 16 of Samsung’s own, which is where our count diverges from the number most outlets are using.

Checklist of the checks this guide runs, in document order
What this guide checks, in the order it checks it.

The figure being reported is 56. We count 54.

Several publications this week put the total at 56, described as 38 Google patches plus 18 Samsung ones. Counting the unique Samsung identifiers listed under the August release on Samsung’s bulletin gives 16, not 18. The Google half matches exactly at 38.

Before treating that as an error by anyone, there is a real ambiguity in the source. Samsung states on the same page that some of the listed items may not be included in a given package, because a patch can appear in the bulletin while shipping to different models at different times. A count taken on a different date, or one that includes items Samsung lists as already delivered in an earlier release, can legitimately land on a different total.

So the honest position is that 38 Google CVEs is firm, and the Samsung-specific number depends on how you count. If a total matters to you, count the bulletin yourself. If it does not, install the update and the arithmetic is somebody else’s problem.

Which phones get it, and when

Samsung describes this release as covering major flagship models, and rollouts move outward from there over following weeks. Samsung does not publish a device-by-device schedule in the bulletin itself, so anyone telling you a firm date for a specific handset is guessing.

The practical version is that flagship Galaxy S and Z devices see it first, recent A series follow, and older or carrier-locked models arrive last. Carrier variants in the United States often lag unlocked models by one to three weeks because the carrier certifies the build separately.

Why installing promptly matters more this month

Eight Critical entries is a heavier month than usual. Google reserves that rating for flaws that can compromise a device without the owner doing anything obviously wrong, which is the category where waiting has an actual cost.

We found no evidence that any of these are being exploited in the wild, and neither Google nor Samsung says so. Absence of an exploitation claim is not the same as absence of exploitation, but it does mean there is no reported active campaign to panic about.

If the update does not appear

Rollouts are staggered, so not seeing it today is normal rather than a fault. Two things actually help. Make sure the phone is on Wi-Fi and above about 30 percent battery, because Samsung gates the download on both. Then check again in a few days rather than repeatedly tapping the button, which does not move you up the queue.

If your security patch level has not moved in several months and your model is still supported, that is a different problem and worth taking to Samsung support rather than waiting it out.

Young man with dark hair outdoors, casual attire, natural background.

I am the chief editor of TheLeaker. I also maintain the backend stuff of the site. I’m a tech enthusiast and loves to do Python coding in my free time. I have worked at many giant publications like XDA Developers and NXTtech before starting TheLeaker.
You can get in touch with me at Garv[at]theleaker.com.