Comment by deng
14 hours ago
I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!
If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.
Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
6 replies →
In a practical sense, what are the consequences of that? If you're careful about not installing random shit on your phone?
It has remotely exploitable vulnerabilities in the firmware, Linux kernel, kernel drivers, userspace drivers and HALs. Those don't require installing anything on your device to exploit. There are publicly available proof of concept exploits for a bunch of these vulnerabilities.
Well, it might be worth it reversing firmwares now with UART pins connected. A lot has changed in (agentic) reverse engineering.
BRB gonna try this out on my old Fairphone
I too have a 4a that is still ticking thanks to Lineage!
The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.
I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.
It's so bad.
What happened there, ... After official support by Google for the 4a stopped, I remember checking LOS out, and found that it wasn't supported there either. Did I hallucinate that, or did LOS resume support afterwards? Or maybe I'm mixing up LOS and graphene
I wish I could still use my Pixel 4a but the battery is pretty much dead and it's too much money to replace it
Prices here are 13EUR including tools from what I can see.
The only reason I have been switching phones is banking apps: so much for Europe's right to repair..
I have yet to find a banking app that refuses to work on LineageOS. The only problem is if you root your phone, in which case you'll have to use Magisk to hide root from those apps, which also works fine so far.
29 replies →
Too lazy to do it myself tbh
1 reply →
Where can one get one for that price range?
1 reply →
+ screen because you WILL break it
2 replies →
I replaced battery in mine for like 90 EUR and several months in dropped it and broke the screen. Would still use it instead of 9a, love how light and compact the phone was. At least now I have a spare phone to root and do stuff with that I couldn't on my main one.
I recently pulled out my Pixel 3 and forgot how much I liked the form factor.
I have a OnePlus 7, and it's chugging along on LOS, otherwise I would be without a smartphone. Heh, fortunately it's still on the supported list
I was secretly hoping I didn't misread and Linaro wiki would be up again, I really wish we could just install mainline linux on those Android phones...
The 4a is a great phone. So thin and light, and even a headphone jack.
Does LOS provide kernel backports or is it limited to userspace?
The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).
[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...
That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.
That's honestly impressive, enough security for a locked down backup phone.
1 reply →