New android security patch level system is a convoluted mess

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Google released today the September edition of the Android Security Bulletin, which starting this month features a new three-level patching string system that is extremely confusing, even for Android professionals.
The "Android security patch level" string is a setting in the phone's "About" section that tells you the date of the last security update your phone received.

Google introduced this string when it started delivering scheduled monthly updates last August.

In May 2016, the company renamed the Nexus Security Bulletin as the Android Security Bulletin to reflect that some of the fixes addressed all Android devices, not just its own.

In July 2015, the company split the bulletin in two, with one section addressing security fixes in core Android files, while the second addressed fixes in device-specific drivers and components. As such, the bulletin featured, for the first time, two security patch levels.September security bulletin fixes 54 security issuesFor this month, lo and behold, the Android Security Bulletin now has three security patch levels that for sure will confuse users.

There's the "2016-09-01" security patch level that includes core security updates for the Android OS.

There's the "2016-09-05" security patch level indicating that a device has received security updates for core files and device-specific drivers.

And there's "2016-09-06" which indicates the phone includes security updates for core files, device-specific drivers, and... we don't know. For this month, the third security patch level includes two bug fixes, one for a critical update for an Android core-related issue, and for a Qualcomm networking component. Doesn't really make sense that much.

Remember, this was the same company that was cited saying it would start shaming OEMs for failing to implement security fixes. Well, Google isn't making their life easier.

..more in the link above....

I believe, indipendent if it makes sense or not, devices need to be updated and not only 2 year old ones.
Manufacturers are bad in providing updates and I still hope this will soon change.
 

soccer97

Level 11
Verified
May 22, 2014
517
I read about this yesterday.

I re-checked the site, It appears they may have updated it and did try to simplify it. 09-06-2016 patch level appears to include all September patches.
Android Security Bulletin

It seems like a "Roll-up" like MSFT.

The security patched "From Google and Samsung" seem to arrive in the Software Updates pushed from carriers (at least here in the US).

Samsung has several to push out as well.

Samsung Android Security Updates
 
  • Like
Reactions: Solarquest

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top