"Google Urges Android Manufacturers to Swiftly Address Security Issues, Closing Patch Gap"

Google's Year in Review report highlights the patch gap issue in the Android ecosystem, where downstream manufacturers take too long to release security fixes provided by upstream vendors. This delay allows publicly known vulnerabilities to function as zero-days, leaving users vulnerable. Google cited examples of delayed patches, including an ARM Mali GPU vulnerability that took 6 months to fix and a Samsung Internet vulnerability caused by using an outdated version of Chromium. The report emphasizes the need for faster distribution of fixes to protect users and highlights the prevalence of variant vulnerabilities that require deeper analysis and thorough fixes.
Reading Insights
0
19
2 min
vs 3 min read
79%
471 → 99 words
Want the full story? Read the original article
Read on 9to5Google