Google just yesterday released the September version of the Android Security Bulletin, which starting this month features a new three-tier patching string system that is extremely confusing, even for Android pros.
The “Android security patch level” string is a setting in the “About” section of your phone that tells you the date of the last security update your phone received.

Google it started delivering its scheduled monthly updates last August.
In May 2016, the company renamed the Nexus Security Bulletin from Android Security Bulletin to make it appear that some of the fixes applied to all Android devices, not just its own.
In July 2015, the company split the Bulletin into two parts, with one part addressing security fixes to the core files , while the second part addressed fixes to device-specific drivers and components. As a result, the Bulletin lists, for the first time, two levels of security patches.
This month's Android Security Bulletin now has three levels of security patches, which is sure to confuse users.
There is the “2016-09-01” security patch level which includes the kernel security updates for the Android OS.
There is the “2016-09-05” security patch level which indicates that a device has received security updates for kernel files and device-specific drivers.
And then there's "2016-09-06," which indicates that the phone includes security updates for kernel files, device-specific drivers, and... we don't know what else. For this month, the third security patch level includes two bug fixes, one for a critical update for an Android kernel issue and one for a Qualcomm networking component.
Remember, this is the same company that was quoted as saying it would start shaming OEMs for failing to apply security patches. Well, Google isn't making its life any easier.
Below you can see a screenshot of an Android device's security patch level string, as well as all the security updates included in this month's security bulletin.
| Remote code execution vulnerability in LibUtils | CVE-2016-3861 | Critical | Yes |
| Remote code execution vulnerability in Mediaserver | CVE-2016-3862 | Critical | Yes |
| Remote code execution vulnerability in MediaMuxer | CVE-2016-3863 | High | Yes |
| Elevation of privilege vulnerability in Mediaserver | CVE-2016-3870, CVE-2016-3871, CVE-2016-3872 | High | Yes |
| Elevation of privilege vulnerability in device boot | CVE-2016-3875 | High | No* |
| Elevation of privilege vulnerability in Settings | CVE-2016-3876 | High | Yes |
| Denial of service vulnerability in Mediaserver | CVE-2016-3899, CVE-2016-3878, CVE-2016-3879, CVE-2016-3880, CVE-2016-3881 | High | Yes |
| Elevation of privilege vulnerability in Telephony | CVE-2016-3883 | Moderate | Yes |
| Elevation of privilege vulnerability in Notification Manager Service | CVE-2016-3884 | Moderate | Yes |
| Elevation of privilege vulnerability in Debuggerd | CVE-2016-3885 | Moderate | Yes |
| Elevation of privilege vulnerability in System UI Tuner | CVE-2016-3886 | Moderate | Yes |
| Elevation of privilege vulnerability in Settings | CVE-2016-3887 | Moderate | Yes |
| Elevation of privilege vulnerability in SMS | CVE-2016-3888 | Moderate | Yes |
| Elevation of privilege vulnerability in Settings | CVE-2016-3889 | Moderate | Yes |
| Elevation of privilege vulnerability in Java Debug Wire Protocol | CVE-2016-3890 | Moderate | No* |
| Information disclosure vulnerability in Mediaserver | CVE-2016-3895 | Moderate | Yes |
| Information disclosure vulnerability in AOSP Mail | CVE-2016-3896 | Moderate | No* |
| Information disclosure vulnerability in Wi-Fi | CVE-2016-3897 | Moderate | No* |
| Denial of service vulnerability in Telephony | CVE-2016-3898 | Moderate | Yes |
| Issue | CVE | Severity | Affects Nexus? |
|---|---|---|---|
| Elevation of privilege vulnerability in kernel security subsystem | CVE-2014-9529, CVE-2016-4470 | Critical | Yes |
| Elevation of privilege vulnerability in kernel networking subsystem | CVE-2013-7446 | Critical | Yes |
| Elevation of privilege vulnerability in kernel netfilter subsystem | CVE-2016-3134 | Critical | Yes |
| Elevation of privilege vulnerability in kernel USB driver | CVE-2016-3951 | Critical | Yes |
| Elevation of privilege vulnerability in kernel sound subsystem | CVE-2014-4655 | High | Yes |
| Elevation of privilege vulnerability in kernel ASN.1 decoder | CVE-2016-2053 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm radio interface layer | CVE-2016-3864 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm subsystem driver | CVE-2016-3858 | High | Yes |
| Elevation of privilege vulnerability in kernel networking driver | CVE-2016-4805 | High | Yes |
| Elevation of privilege vulnerability in Synaptics touchscreen driver | CVE-2016-3865 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm camera driver | CVE-2016-3859 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm sound driver | CVE-2016-3866 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm IPA driver | CVE-2016-3867 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm power driver | CVE-2016-3868 | High | Yes |
| Elevation of privilege vulnerability in Broadcom Wi-Fi driver | CVE-2016-3869 | High | Yes |
| Elevation of privilege vulnerability in kernel eCryptfs filesystem | CVE-2016-1583 | High | Yes |
| Elevation of privilege vulnerability in NVIDIA kernel | CVE-2016-3873 | High | Yes |
| Elevation of privilege vulnerability in Qualcomm Wi-Fi driver | CVE-2016-3874 | High | Yes |
| Denial of service vulnerability in kernel networking subsystem | CVE-2015-1465, CVE-2015-5364 | High | Yes |
| Denial of service vulnerability in kernel ext4 file system | CVE-2015-8839 | High | Yes |
| Information disclosure vulnerability in Qualcomm SPMI driver | CVE-2016-3892 | Moderate | Yes |
| Information disclosure vulnerability in Qualcomm sound codec | CVE-2016-3893 | Moderate | Yes |
| Information disclosure vulnerability in Qualcomm DMA component | CVE-2016-3894 | Moderate | Yes |
| Information disclosure vulnerability in kernel networking subsystem | CVE-2016-4998 | Moderate | Yes |
| Denial of service vulnerability in kernel networking subsystem | CVE-2015-2922 | Moderate | Yes |
| Vulnerabilities in Qualcomm components | CVE-2016-2469 | High | No |
| Issue | CVE | Severity | Affects Nexus? |
|---|---|---|---|
| Elevation of privilege vulnerability in kernel shared memory subsystem | CVE-2016-5340 | Critical | Yes |
| Elevation of privilege vulnerability in Qualcomm networking component | CVE-2016-2059 | High | Yes |

