129 CVEs patched in a single Android security update. That's the most in a month since April 2018.
One's a Qualcomm zero-day (CVE-2026-21385) integer overflow in the display component, already being exploited in the wild, affects 230+ chipsets.
One's an RCE in Media Codecs (CVE-2026-0006) no user interaction required.
The good news: Project Mainline handled the Media Codecs patch OTA via the Play Store, no waiting for your carrier.

Florence Ion wrote it up in full in this week's Android Faithful newsletter. It's free, it drops every Friday, and it's the sharpest Android coverage out there.
Get the details and Subscribe → https://www.androidfaithful.com/androids-biggest-spring-cleaning-in-years/

#Android #InfoSec #CVE #ProjectMainline #AndroidSecurity

Android's Biggest Spring Cleaning in Years

A record-breaking 129 reasons why Project Mainline is paying off.

Android Faithful