Some Android Phones Are Missing Security Patches They Claim to Have

Some Android Phones Are Missing Security Patches They Claim to Have

Google stepped up its scrutiny of device security several years ago in the wake of the massive Stagefright vulnerability. Ever since then, Android devices list a “patch level” that tells you when its security was last updated. However, Karsten Nohl and Jakob Lell Security Research Labs say that many devices are fibbing about their security patches. Some phones are missing more than a dozen patches.

Each month, Google puts out a new list of Android patches, some of which are minor and others may be critical vulnerabilities. Google rolls these patches out to its Pixel phones right away, but most manufacturers are at least a few months behind. When the update does arrive on a phone, the settings reports the patch level as a month and year. For example, if your phone says you have April 2018 patches, it should be protected from all vulnerabilities reported in Google’s April security bulletin and earlier.

Nohl and Lell have spent two years reverse engineering the updates on more than 1,200 Android phones to see if those patches are all included. They’ve identified a “patch gap” where devices report a specific patch level, but they aren’t protected from all the bugs indicated by that patch date. In some cases, the patch level was a good indicator of a device’s security, but certain devices were missing more patches than you’d expect.

Security Research Labs created the table below to break manufacturers up into groups based on the average number of missing patches on their phones (in 2017 patches). Unsurprisingly, Google never misses patches on its phones, and they’re delivered fastest. Sony, Samsung, and Wiko also averaged between 0 and 1 missing patches. Xiaomi, OnePlus, and Nokia also fare well with 1-3 missing patches. HTC, Huawei, LG, and Motorola are in the 3-4 missing patch group. Then at the bottom, you’ve got TCL and ZTE with an average of 4 or more missing patches.

Some Android Phones Are Missing Security Patches They Claim to Have

You could reasonably believe most of this is just an accident and not a result of incompetence or malicious behavior. However, Nohl and Lell found some low-cost phones got updates that were not vetted properly. For example, the Samsung Galaxy J3 missed 12 patches in 2017 that it claimed to have.

There’s one more wrinkle here: the type of chip in a phone makes a difference. Nohl and Lell found that phones shipping with the less expensive MediaTek processors had a much higher incidence of missing patches — an average of 9.7 of them. Device makers rely on chip vendors to release patches for their designs, and MediaTek is notoriously slow to comply with open source requirements.

Does this mean your phone is dangerously insecure? Nohl and Lell don’t think so. Most devices still have almost all the patches you’d expect, and the Android platform has protections like address space layout randomization and process sandboxing to foil attacks. Google should still hold some feet to the fire, though.

Continue reading

Android 12 Could Include Major App Compatibility Improvements
Android 12 Could Include Major App Compatibility Improvements

Google has attempted to centralize chunks of Android over the years, and a major component called ART is set to get this treatment in Android 12. The result could be vastly improved app compatibility, which is sure to make everyone happy.

Qualcomm’s New Snapdragon 888 Will Power Flagship Android Phones in 2021
Qualcomm’s New Snapdragon 888 Will Power Flagship Android Phones in 2021

The 888 comes with a new CPU design, integrated 5G, and a massive GPU boost. It's shaping up to be the most significant update to Qualcomm's flagship system-on-a-chip (SoC) in years.

Samsung Starts Rolling Out Galaxy S20 Android 11 Update on Verizon
Samsung Starts Rolling Out Galaxy S20 Android 11 Update on Verizon

Not only does this include the Googley Android 11 enhancements, but it also has numerous Samsung-specific changes as part of the One UI 3.0 revamp.

It Turns Out Huawei’s HarmonyOS Is Still Just Android
It Turns Out Huawei’s HarmonyOS Is Still Just Android

Following the Commerce Department's actions against the Chinese megafirm, Huawei has been unable to use Google services on its new phones. The company's solution was to develop HarmonyOS, but now that we've gotten our first real look at it, one thing is clear: this is just Android with a skin.