← Back to context

Comment by Retr0id

17 hours ago

Google is also seriously dropping the ball in terms of security. The CVE-2026-43499 root LPE (aka ghostlock) is still unpatched across all Pixel devices, on the latest """security""" update, despite weaponized exploits being public for months.

Pixels used to have far better updates than any other Android devices but they stopped improving it years ago. It should have kept improving because it's not at all adequate. They need to be able to release OS updates more than once per month and it shouldn't take months for patches to make it into the OS. It currently takes them at least around 2 months to get even the most urgent patches into the OS. They could fix emergency calls being broken if the patch was made around 3 weeks before an OS release, but that's about as quick as they can go. It's not at all adequate for security and is a complete joke compared to Chromium's release cycle. They can get an emergency Chrome update released within a couple days. They should at least be able to do it for the Pixel OS in a week.

GrapheneOS is often around 4 to 6 months ahead on merging Linux kernel LTS releases. We used to handle this ourselves but switched to the Android GKI LTS branch maintained by Greg KH. Unfortunately, it was often struggling to keep up even before the absolutely massive increase in Linux kernel security patches this year. AI models have rapidly accelerated vulnerability discovery and it's an ongoing crisis for the Linux kernel. We want to be on the latest LTS revision within days and want to be using the latest LTS branch within months of it being released. We're not at all happy with how Android is handling things and plan to fix that ourselves. We'll get things back to how they should be.

We also ship all the AOSP userspace patches months before Pixels due to shipping all of the security preview patches as soon as possible. There are sometimes minor regressions but we find and fix them ourselves downstream. The security preview system has a terrible design especially considering that frontier AI models can reverse engineer the patches. There should at least only be a source embargo for around 24 to 72 hours rather than pretending as if it can work with the patches available 2 to 6 months in advance.

  • I'd love to use GrapheneOS on less secure devices, just for the sake of Google autonomy rather than privacy.

    • GrapheneOS will be available on Motorola devices meeting all of our requirements for updates and security features in 2027. It will be starting out on a high end flagship and expanding down from there as devices improve to meet our requirements. We aren't going to support devices unable to provide a reasonable level of security.

      2 replies →

    • Same thing here, I use Graphene for the sake of user control. All the security features and hardening of the Pixel phones and of the OS are good to have, but they not the main reason.

      1 reply →

    • You can dot his but it won't be Graphene but something else, like LineageOS. As long as Graphene's selling point is extreme privacy and not just more privacy, it will be this way.

      1 reply →

I just ran https://github.com/CakesTwix/Android-CVE-2026-43499 on my Pixel 9 Pro and it seems to have been patched. I did get a system update not long ago, though.

  • Try https://github.com/alex193a/Root-My-Pixel, worked on my 9a as of a few days ago (the version table in the readme is stale). I haven't checked the September update yet though (installing it now, to check).

    Edit: September update for 8a has a kernel build from July. I believe it's still vulnerable but the exploit will need its offsets adjusting etc.

There's "dropping the ball" and then there's "not reaching out your glove to catch it to begin with".

It'd be interesting to see which one is happening here.