top of page
Search
  • Writer's pictureTech Glass

How Monthly Android Security Patch Updates Work !!



Source: XDA

Google has been publishing monthly security bulletins since August of 2015. These security bulletins contain a list of disclosed security vulnerabilities that have been fixed which affect the Android framework, Linux kernel, and other closed-source vendor components. Every vulnerability in the bulletins was either discovered by Google or disclosed to the company. Every vulnerability listed has a Common Vulnerabilities and Exposures (CVE) number, along with associated references, the type of vulnerability, a severity assessment, and the AOSP version affected (if applicable). But despite the seemingly simplistic process behind how Android security patches work, there’s actually a somewhat complicated back-and-forth behind the scenes that allows for your phone to get monthly or (hopefully) near-monthly patches.

What actually makes a security patch?

You may have noticed that every month, there are actually two security patch levels. The format of these patches is either YYYY-MM-01 or YYYY-MM-05. While the YYYY and MM obviously represent the year and month respectively, the “01” and “05” confusingly does not actually signify the day of the month in which that security patch level was released. Instead, the 01 and 05 are actually two different security patch levels released on the same day every month – the patch level with 01 at the end contains fixes to the Android framework but not vendor patches or upstream Linux kernel patches. Vendor patches, as we defined above, refer to fixes to closed-source components such as drivers for Wi-Fi and Bluetooth. The security patch level signified by -05 contains these vendor patches as well as patches in the Linux kernel. Take a look at the table below which may help in understanding.

Monthly Security Patch Level2019-04-012019-04-05Contains April Framework PatchesYesYesContains April Vendor + Kernel PatchesNoYesContains March Framework PatchesYesYesContains March Vendor + Kernel PatchesYesYes

Of course, some OEMs may opt to roll their own patches and updates into security updates as well. Most OEMs have their own take on Android, so it only makes sense that you may have, for example, a vulnerability on a Samsung phone that doesn’t exist on a Huawei. A lot of these OEMs also publish their own security bulletins.

The timeline of a security patch from Google to your phone

Security patches have a timeline roughly spanning about 30 days, though not every OEM can avail of the full length of that timeline. Let’s take a look at the May 2019 security patch for example, and we can break down the entire timeline behind the creation of this patch. Companies like Essential manage to get out their security updates on the same day as the Google Pixel, so how do they do it? The short and simple answer is that they’re an Android partner. The May 2019 security bulletin was published on the 6th of May, with both the Google Pixels and the Essential Phone getting near-immediate updates.

What it means to be an Android Partner

Not just any company can be an Android Partner, though admittedly basically every major Android OEM is. Android Partners are the companies that are granted a license to use the Android branding in marketing material. They are also allowed to ship Google Mobile Services (GMS – refers to pretty much all Google services) so long as they meet the requirements outlined in the Compatibility Definition Document (CDD) and pass the Compatibility Test Suite (CTS), Vendor Test Suite (VTS), Google Test Suite (GTS), and a few other tests. There are distinct differences in the security patch process for companies that aren’t an Android Partner.

  • Android framework patches are available to them after being merged into AOSP 1-2 days before the security bulletin is released.

  • Upstream Linux kernel patches can be cherry-picked once available.

  • Fixes from SoC vendors for closed-source components are available depending on agreements with the SoC vendor. Note that if the vendor has given the OEM access to the source code of the closed-source component(s), then the OEM can fix the issue(s) themselves. If the OEM does not have access to the source code, then they must wait for the vendor to issue a fix.

If you are an Android Partner, you immediately have it a whole lot easier. Android partners are notified of all Android framework issues and Linux kernel issues at least 30 days before the bulletin is made public. Google provides patches for all issues for OEMs to merge and test, though vendor component patches are dependent on the vendor. Patches for the Android framework issues disclosed in the May 2019 security bulletin, for example, were provided to Android partners at least as early as March 20th, 2019*. That’s a lot of extra time.

1 view0 comments

Comments


Apple iPhone Event under 9 Minutes : iPhone 12, iPhone 12 Pro and iPhone 12 Mini details | TechGlass
08:25

Apple iPhone Event under 9 Minutes : iPhone 12, iPhone 12 Pro and iPhone 12 Mini details | TechGlass

Apple today announced the new iPhone 12, featuring a 6.1-inch OLED display. The iPhone 12 is one of four models unveiled today as part of the new fall iPhone lineup. iPhone 12 will go on sale for $799, and the smaller iPhone 12 mini starts at $699. iPhone 12 will be available to order starting this Friday, October 16. All new iPhones support 5G and feature a new industrial design with flat edges and thinner bezels. The phone looks a lot like an iPhone 5 but with a full-screen face. The iPhone 12 comes in five color finishes: black, white, red, green and blue. Whereas the iPhone 12 Pro features a stainless steel frame, the cheaper iPhone 12 continues to use aluminium case materials. Source : Apple/Verge =================================== Check out our other videos: 7 Top iOS14 features from Android : https://youtu.be/u8GWLnM427A How to get iOS 14 NOW before its official release : https://youtu.be/DqKEDX938gs FREE : How to watch YouTube without Ads for FREE : https://youtu.be/mehfU1tsKLI Top 6 Reasons to use Google Meet : https://youtu.be/p278-MTEKA4 Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo Presenting OLA Select : https://youtu.be/H1zixovCvgw
How to get iOS 14 NOW before its official release | TechGlass
02:21

How to get iOS 14 NOW before its official release | TechGlass

Apple released lots of features as part of iOS14, but the official release of iOS14 is going to happen later this year in September if all goes well with rest of 2020 !! How about getting the iOS14 right on your phone, right now ? Yes, you can, here is how you can install iOS14 Beta on you phone in just 2 minutes. Go ahead and get that iOS14 feeling you have been waiting for !! Please note : Beta builds are not as stable as the actual releases, please make sure you take backup of your phone before installing beta software on the phone. Also, we recommend not to install beta profile on your primary phone. You will be solely responsible for any issue/problem/damage to your phone. =============================== Check out our other videos: FREE : How to watch YouTube without Ads for FREE : https://youtu.be/mehfU1tsKLI Top 6 Reasons to use Google Meet : https://youtu.be/p278-MTEKA4 Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo Presenting OLA Select : https://youtu.be/H1zixovCvgw ================ Follow us on Facebook : https://m.facebook.com/TechGlasss Twitter : https://www.twitter.com/techglass1 Instagram : https://www.instagram.com/thetechglass
Top 6 reasons to use Google Meet | TechGlass
02:43

Top 6 reasons to use Google Meet | TechGlass

Skip the Zoom drama and Meet a better way to video chat. Living alone, the only way I see my friends and family right now is video chatting apps, and there certainly are plenty to choose from these days. Zoom has been the in-vogue video app of the last several weeks, but since that Google Meet is free for everyone this summer, you should absolutely move your chats over to Meet instead. While Google Meet was built for enterprise as a way to host weekly staff meetings and host company-wide briefings, it has several advantages for the everyday chat with your parents or that weekly coffee gossip your mom has with her friends. The only reason not to give Google Meet a shot right now is actually that many of us actually can't create video meetings yet. Google said in its announcement that the ability for non-G Suite users to use Google Meet for more than joining someone else's meeting is going to be gradually rolling out over the next few weeks. ================================ Check out our other videos: Zoom Video Conferencing : Should you Zoom In or Zoom Out : https://youtu.be/nVPrl8NgDoY Google Smart Debit Card : https://youtu.be/HjTEhC06dYQ DIY Surgical Mask under 2 minutes : https://youtu.be/tHTW1dL_Twk iPhone SE launch : https://youtu.be/b8ZBNbymsDk YouTube Short - TikTok alternative : https://youtu.be/uxxvUpVVas8 OnePlus8 Colors : https://youtu.be/P8RhIRwOsFg How to book OLA and Uber directly from Google Maps : https://youtu.be/gseqGb59Kvo
bottom of page