Xiaomi has started rolling out the September 2026 security update firstly for the REDMI K80 in China. The update carries the build number OS3.0.308.0.WOKCNXM and targets devices running HyperOS 3.
Critical Android Framework Fixes
This patch addresses multiple critical vulnerabilities in the Android Framework and system components. Notably, it fixes several Remote Code Execution (RCE) flaws including CVE-2026-28604, CVE-2026-28618, and CVE-2026-28639. These critical RCE bugs could allow attackers to run malicious code on the device without user interaction or extra privileges.
In addition, the update resolves Elevation of Privilege (EoP) issues like CVE-2026-28666 and CVE-2026-55273. These vulnerabilities previously let malicious apps gain unauthorized system permissions silently, risking private user data exposure.
Kernel and Google Play System Updates
The September patch also fixes kernel-level weaknesses that could enable privilege escalation within the Protected Kernel-Based Virtual Machine (pKVM) and NFC modules. Examples include CVE-2026-31629 and CVE-2026-58846.
Project Mainline components such as Media Framework, Media Codecs, Wi-Fi, and Ultra-wideband (UWB) have received targeted fixes delivered via Google Play system updates. These address vulnerabilities that could cause Denial of Service (DoS) or enable RCE attacks.
Chipset and GPU Vendor Security Patches
The update integrates security patches from hardware vendors essential to device safety:
- Qualcomm: Fixed a critical vulnerability (CVE-2026-25289) in proprietary components alongside several high-severity chipset issues.
- MediaTek: Patched high-severity flaws affecting modems, HEVC decoders, AI processing units, trusted memory, and imaging systems.
- ARM & Imagination Technologies: Corrected multiple high-severity bugs in ARM Mali and PowerVR GPUs, preventing possible memory corruption attacks.
- Unisoc & Tsingteng Micro: Addressed modem vulnerabilities and a StrongBox security module flaw, enhancing device integrity.
Availability and Further Information
The update is currently limited to REDMI K80 devices in China running HyperOS 3. Users can check and install the latest build via system update settings. For those tracking update releases and firmware packages, the build OS3.0.308.0.WOKCNXM and security patch tracker details can be monitored on MemeOSUpdates.com. HyperOS users may also verify update availability through the MemeOS Enhancer app.

