Some Android Phones Are Missing Security Patches They Claim to Have

Some Android Phones Are Missing Security Patches They Claim to Have

Google stepped up its scrutiny of device security several years ago in the wake of the massive Stagefright vulnerability. Ever since then, Android devices list a “patch level” that tells you when its security was last updated. However, Karsten Nohl and Jakob Lell Security Research Labs say that many devices are fibbing about their security patches. Some phones are missing more than a dozen patches.

Each month, Google puts out a new list of Android patches, some of which are minor and others may be critical vulnerabilities. Google rolls these patches out to its Pixel phones right away, but most manufacturers are at least a few months behind. When the update does arrive on a phone, the settings reports the patch level as a month and year. For example, if your phone says you have April 2018 patches, it should be protected from all vulnerabilities reported in Google’s April security bulletin and earlier.

Nohl and Lell have spent two years reverse engineering the updates on more than 1,200 Android phones to see if those patches are all included. They’ve identified a “patch gap” where devices report a specific patch level, but they aren’t protected from all the bugs indicated by that patch date. In some cases, the patch level was a good indicator of a device’s security, but certain devices were missing more patches than you’d expect.

Security Research Labs created the table below to break manufacturers up into groups based on the average number of missing patches on their phones (in 2017 patches). Unsurprisingly, Google never misses patches on its phones, and they’re delivered fastest. Sony, Samsung, and Wiko also averaged between 0 and 1 missing patches. Xiaomi, OnePlus, and Nokia also fare well with 1-3 missing patches. HTC, Huawei, LG, and Motorola are in the 3-4 missing patch group. Then at the bottom, you’ve got TCL and ZTE with an average of 4 or more missing patches.

Some Android Phones Are Missing Security Patches They Claim to Have

You could reasonably believe most of this is just an accident and not a result of incompetence or malicious behavior. However, Nohl and Lell found some low-cost phones got updates that were not vetted properly. For example, the Samsung Galaxy J3 missed 12 patches in 2017 that it claimed to have.

There’s one more wrinkle here: the type of chip in a phone makes a difference. Nohl and Lell found that phones shipping with the less expensive MediaTek processors had a much higher incidence of missing patches — an average of 9.7 of them. Device makers rely on chip vendors to release patches for their designs, and MediaTek is notoriously slow to comply with open source requirements.

Does this mean your phone is dangerously insecure? Nohl and Lell don’t think so. Most devices still have almost all the patches you’d expect, and the Android platform has protections like address space layout randomization and process sandboxing to foil attacks. Google should still hold some feet to the fire, though.

Continue reading

New macOS Security Bug Unlocks App Store With Any Password
New macOS Security Bug Unlocks App Store With Any Password

Apple's macOS High Sierra has a flaw in the latest version that allows admin users to bypass a locked app store by entering any password they like.

Researchers Found Another Major Security Flaw in Intel CPUs
Researchers Found Another Major Security Flaw in Intel CPUs

Security researchers have found another flaw in Intel CPUs — this time related to Intel Active Management Technology. Once again, this flaw can be leveraged to take complete control of a system, regardless of any security measures the user might employ.

Lawmakers Urge AT&T to Cut Ties with Huawei, Citing National Security Concerns
Lawmakers Urge AT&T to Cut Ties with Huawei, Citing National Security Concerns

It's been several years since the last dust-up, but US lawmakers and regulators are still sounding the alarm about any cooperation with Huawei.

Most Android Security Scares Are Bullshit
Most Android Security Scares Are Bullshit

Many of the Android malware stories we see making the rounds end up amounting to nothing because of the way the platform operates these days. While Android malware is definitely out there, you usually don't need to panic.