Xiaomi started to release September 2026 security patch for HyperOS 3

Xiaomi has started rolling out the September 2026 security update firstly for the REDMI K80 in China. The update carries the build number OS3.0.308.0.WOKCNXM and targets devices running HyperOS 3.

Critical Android Framework Fixes

This patch addresses multiple critical vulnerabilities in the Android Framework and system components. Notably, it fixes several Remote Code Execution (RCE) flaws including CVE-2026-28604, CVE-2026-28618, and CVE-2026-28639. These critical RCE bugs could allow attackers to run malicious code on the device without user interaction or extra privileges.

In addition, the update resolves Elevation of Privilege (EoP) issues like CVE-2026-28666 and CVE-2026-55273. These vulnerabilities previously let malicious apps gain unauthorized system permissions silently, risking private user data exposure.

Kernel and Google Play System Updates

The September patch also fixes kernel-level weaknesses that could enable privilege escalation within the Protected Kernel-Based Virtual Machine (pKVM) and NFC modules. Examples include CVE-2026-31629 and CVE-2026-58846.

Project Mainline components such as Media Framework, Media Codecs, Wi-Fi, and Ultra-wideband (UWB) have received targeted fixes delivered via Google Play system updates. These address vulnerabilities that could cause Denial of Service (DoS) or enable RCE attacks.

Chipset and GPU Vendor Security Patches

The update integrates security patches from hardware vendors essential to device safety:

  • Qualcomm: Fixed a critical vulnerability (CVE-2026-25289) in proprietary components alongside several high-severity chipset issues.
  • MediaTek: Patched high-severity flaws affecting modems, HEVC decoders, AI processing units, trusted memory, and imaging systems.
  • ARM & Imagination Technologies: Corrected multiple high-severity bugs in ARM Mali and PowerVR GPUs, preventing possible memory corruption attacks.
  • Unisoc & Tsingteng Micro: Addressed modem vulnerabilities and a StrongBox security module flaw, enhancing device integrity.

Availability and Further Information

The update is currently limited to REDMI K80 devices in China running HyperOS 3. Users can check and install the latest build via system update settings. For those tracking update releases and firmware packages, the build OS3.0.308.0.WOKCNXM and security patch tracker details can be monitored on MemeOSUpdates.com. HyperOS users may also verify update availability through the MemeOS Enhancer app.

MemeOS Enhancer Download
Avatar for Emir Bardakçı

Emir Bardakçı

Co-founder & HyperOS Expert

Keeping a pulse on Xiaomi, HyperOS, and the Android world. Tech enthusiast, photography lover, and detailed reviewer.

Comments
  • Nélson Da Silva Roque Morgado 26 seconds ago

    When will HiperOs 3.1 European version Portugal be released for Redmi 14c?

    Reply
    (0)
    Dislike (0)
  • Nélson Da Silva Roque Morgado 4 seconds ago

    When will the European version 3.1 of hiperOs for Redmi 14c be released in Portugal?

    Reply
    (0)
    Dislike (0)

Leave a Reply

Your email address will not be published. Required fields are marked *