Comment by microtonal

2 days ago

Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.

> There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery.

These are not rumors. It's an official announcement from Google to OEMs and we have access to it.

> Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

Aren't those back-ported for a while?

  • Android Security Bulletins are a list of the High and Critical severity patches backported to older Android versions. At the time a bulletin is published, the patches have been available to OEMs to ship for 2-4 months. Fairphone is nearly always 1-2 months behind the latest bulletin but it can get much worse over time.

    Android Security Bulletins do not cover the vast majority of Linux kernel security patches. They only cover an extremely small subset tied to Android. The Linux kernel has a massive tsunami of security patches on an ongoing basis. Fairphone 5 and earlier have an end-of-life Linux kernel without security support. They're close to not updating the kernel at all anymore. Their more recent devices will end up in the same situation.

    The Linux kernel is not the only component ending up unmaintained while the devices are still presented as supported.