Some Android Phones Are Missing Security Patches They Claim to Have

Some Android Phones Are Missing Security Patches They Claim to Have

Google stepped up its scrutiny of device security several years ago in the wake of the massive Stagefright vulnerability. Ever since then, Android devices list a “patch level” that tells you when its security was last updated. However, Karsten Nohl and Jakob Lell Security Research Labs say that many devices are fibbing about their security patches. Some phones are missing more than a dozen patches.

Each month, Google puts out a new list of Android patches, some of which are minor and others may be critical vulnerabilities. Google rolls these patches out to its Pixel phones right away, but most manufacturers are at least a few months behind. When the update does arrive on a phone, the settings reports the patch level as a month and year. For example, if your phone says you have April 2018 patches, it should be protected from all vulnerabilities reported in Google’s April security bulletin and earlier.

Nohl and Lell have spent two years reverse engineering the updates on more than 1,200 Android phones to see if those patches are all included. They’ve identified a “patch gap” where devices report a specific patch level, but they aren’t protected from all the bugs indicated by that patch date. In some cases, the patch level was a good indicator of a device’s security, but certain devices were missing more patches than you’d expect.

Security Research Labs created the table below to break manufacturers up into groups based on the average number of missing patches on their phones (in 2017 patches). Unsurprisingly, Google never misses patches on its phones, and they’re delivered fastest. Sony, Samsung, and Wiko also averaged between 0 and 1 missing patches. Xiaomi, OnePlus, and Nokia also fare well with 1-3 missing patches. HTC, Huawei, LG, and Motorola are in the 3-4 missing patch group. Then at the bottom, you’ve got TCL and ZTE with an average of 4 or more missing patches.

Some Android Phones Are Missing Security Patches They Claim to Have

You could reasonably believe most of this is just an accident and not a result of incompetence or malicious behavior. However, Nohl and Lell found some low-cost phones got updates that were not vetted properly. For example, the Samsung Galaxy J3 missed 12 patches in 2017 that it claimed to have.

There’s one more wrinkle here: the type of chip in a phone makes a difference. Nohl and Lell found that phones shipping with the less expensive MediaTek processors had a much higher incidence of missing patches — an average of 9.7 of them. Device makers rely on chip vendors to release patches for their designs, and MediaTek is notoriously slow to comply with open source requirements.

Does this mean your phone is dangerously insecure? Nohl and Lell don’t think so. Most devices still have almost all the patches you’d expect, and the Android platform has protections like address space layout randomization and process sandboxing to foil attacks. Google should still hold some feet to the fire, though.

Continue reading

NASA Created a Collection of Spooky Space Sounds for Halloween
NASA Created a Collection of Spooky Space Sounds for Halloween

NASA's latest data release turns signals from beyond Earth into spooky sounds that are sure to send a chill up your spine.

Astronomers Might Finally Know the Source of Fast Radio Bursts
Astronomers Might Finally Know the Source of Fast Radio Bursts

A trio of new studies report on an FRB within our own galaxy. Because this one was so much closer than past signals, scientists were able to track it to a particular type of neutron star known as a magnetar.

Sony’s PlayStation 5 Debuts to Strong Reviews
Sony’s PlayStation 5 Debuts to Strong Reviews

Reviews have come in for Sony's PlayStation 5, and while they're a bit preliminary for the same reason as the Xbox Series X, they're broadly positive about Sony's latest gaming effort.

How to Build a Face Mask Detector With a Jetson Nano 2GB and AlwaysAI
How to Build a Face Mask Detector With a Jetson Nano 2GB and AlwaysAI

Nvidia continues to make AI at the edge more affordable and easier to deploy. So instead of simply running through the benchmarks to review the new Jetson Nano 2GB, I decided to tackle the DIY project of building my own face mask detector.