The Register Home Page

back to article Android drops mega patch bomb - 120 fixes, two already exploited

Patch Tuesday is next week, but Android is ahead of the game, dropping its biggest patch bundle this year while attackers actively exploit two of the now-fixed flaws. This month, the world's most popular mobile operating system pushed out 120 patches, its biggest monthly dump this year. It's a far cry from July, when Android …

  1. Anonymous Coward
    Anonymous Coward

    Google should have...

    Google should have, at the very least, listed how the miscreants are attacking. My guess is that its via MMS, where you can attack 144 devices at once.

    1. ChrisElvidge Silver badge

      Re: Google should have...

      That would be gross.

  2. ComputerSays_noAbsolutelyNo Silver badge

    Shitty computers

    "Smartphones" are enshittyfied computers, where any OS update needs to filter through the vendor. If the vendor descides not to give a proverbial, then you're stuck with a vilnerable device, that's technically still in support.

    Pathetic

    1. Vader

      Re: Shitty computers

      Yep. The way it should is the core is updated by google directly and then extras the layer that the manufacturer has added is there problem.

    2. bazza Silver badge

      Re: Shitty computers

      That's not an inherent property of the concept of a smartphone.

      MS tried quite hard to standardise smartphone hardware so that one OS vendor could distribute their OS to whole swathes of hardware. Just like Linux and Windows can be rolled out across PCs. Naturally MS were hoping that this would give them a winning leg up in the race to participate in the Smartphone market, but it didn't work. Technically, it was just fine and could have gone places.

      What's disappointing about the government regulators is that they do not seem interested in such things. The PC is a hardware standard (originally accidentally made by IBM, and then formalised by Microsoft for the benefit of the whole market [with them at the top of that market]), and that's benefited many. It's the primary reason Linux was able to establish a foothold. But regulators seem to have been content to let companies like Apple, Google and Samsung roll that hardware openness back. That's not been good for the consumer.

  3. Anonymous Coward
    Anonymous Coward

    That first CVE has been in Linux from 2.6.36, best part of 16 years. That's a long, long time for such a vulnerability to be there. It's also in an area likely to have been of interest to those actively hunting exploitable opportunities; timers and their deletion feels like a ripe area for finding race conditions. If one were to be paranoid about whether this has been exploited on one's systems or not, 16 years is a long time to look back over for signs of intrusion, privilege escalation, etc.

    1. Anonymous Coward
      Anonymous Coward

      So it could be argued that it has only been fixed because they found a way to install another backdoor?

      Well, it IS Google..

  4. mark l 2 Silver badge

    Well hopefully since i run LineageOS I will get these patches soon, as the devs there are usually really good at pushing out updates. But that just goes to show something when a group of volunteers doing this in their free time are faster at pushing out updates than large phone manufactures than make millions of dollars a year in profit.

  5. Ol'Peculier

    Bloody 'ell, the update size is 0.97GB on my Pixel 9.

    Is it upgrading the entire system?!

    1. /\/\j17

      Not far off.

      In addition to the bug fixes there's quite a lot of UI changes, fron the base font up (having just installed it on my Pixel 7 Pro).

      Let's just hope it sorts out some of the battery life and device temerature issues they introduced with Android 16!

    2. Martin an gof Silver badge

      Is it upgrading the entire system?!

      I believe that's the way Android is updated, so even a relatively quiet update cycle will have the same download size. Certainly it's what Lineage does; "updates" are actually the entire system, ready to go. They are installed alongside the running system and the reboot then swaps over to the new image a bit like updating the firmware in your network switch or router or other "appliance" type device. Lineage images for my second-hand Motorola phone are currently 0.97GB (v22.2), up from 0.92GB for v21.0 and slightly lower again (can't remember offhand) when the phone was on v20.

      M.

      1. nowster

        On Pixels it's usually a differential patch against the currently installed system partition. Many patch updates are tiny (<50MB). Android version upgrades tend to be large (~1GB).

        There are two system partitions, and an update writes to the one not currently in use, then at the end of a successful update process the bootloader is switched to booting from the one just written to.

  6. a_foley
    Trollface

    Just like Mr. Cook said…

    ”Buy your mom an iPhone”

  7. dmesg Bronze badge

    Thank you El Reg, for reporting on this. Please keep up the pressure on vendors (and FOSS projects) to fix these flaws.

    Might I suggest a standing feature for the site? An easily locatable link leading to an "Update Wall of Shame", listing laggards who leave 9.0+ vulnerabilities unpatched too long, with details. Might be very useful in purchase specification: vendors appearing on the list are not considered, or require high-level sign-off. Even just alerting Our Betters to a preferred vendor's presence would provide valuable CYA.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like