Earlier quoted context omitted.
iOS and Windows Phone architecture are already much better than Android in this regard. Also Symbian had a relatively good security architecture, with its micro-kernel and the permissions model introduced in S60 v3. Android security lags behind, because Google doesn't want to force OEMs and providers to provide updates. Additionally the OS architecture makes it pretty easy to extract an APK and reverse engineer it, e…
> Android security lags behind, because Google doesn't want to force OEMs and providers to provide updates. What do OEM updates have to do with a security hole in Chrome ? Despite all the merger chatter, Chrome isn't an OS-level part Android the way it is with ChromeOS. The exploit sounds serious, but once the Chrome team understands it and comes up with a fix, all Google needs to do to deploy it is publish a new ver…
Second, most mobile users use whatever app is labeled as "Internet" on their phones and tablets. Only savy users get to install Chrome.
Third, anyone using an Android system older than Lollipop won't get WebView updates.
So on those devices a Chrome update is indeed an OS update.