Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

101–110 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#101

I'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?

Search CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.

What if an existing app gets an update that exploits the vulnerability?

For sure that's not going to happen to an app released by a major company, but there are lots of less known app created by many different developers.

Re: Google confirms Android attacks; no fix for most Samsung users

#102

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

Whilst the play store supposedly scans all apps for malicious behaviour, it's pretty easy to detect the test environment they use for testing and make malicious behaviour only trigger in situations Google doesn't test - eg. 5 days after installation, only if the device IP address changes at least once.

I'd imagine the dalvik part to be pretty open to static analysis?

On the desktop JVM, I've seen bytecode that decompiled to a form more readable than the original source I got access to later...

Re: Google confirms Android attacks; no fix for most Samsung users

#103
post #8

While the information leakage/disclosure is a big issue, It feels like its still a big jump to get users to install off-Play Store APKs?

Considering there was a whole hubbub starting from late Aug 2025 RE: Certification of ALL Android apps/.apks: https://android-developers.googleblog.com/2025/08/elevating-...

Followed by a partial walk-back from Google in mid Nov 2025: https://android-developers.googleblog.com/2025/11/android-de...

I would say there is a substantial amount of users willing to install off-play Store .APKs. Substantial enough they're also willing to take a 'jump' and accept the risks/errors displayed

Re: Google confirms Android attacks; no fix for most Samsung users

#104
post #97

Earlier quoted context omitted.

Unfortunately, even with the best after-market support, banking apps and/or contactless payments becomes a cat-and-mouse game, that, even if it works, can stop working at the drop of a hat.

I can tell you that Wells Fargo works both on Lineage with Mind the Gapps, and Graphene with the Play store installed. I have it on my OnePlus 5 and Pixel 6a. I understand that most U.S. banking apps work on Graphene. As far as contactless payments, try a Pixel watch. I understand that it is entirely separate from the phone.

Provisioning payment cards on your watch without being able to run the phone app will be quite a challenge, however!

Re: Google confirms Android attacks; no fix for most Samsung users

#106
post #97

Earlier quoted context omitted.

I can tell you that Wells Fargo works both on Lineage with Mind the Gapps, and Graphene with the Play store installed. I have it on my OnePlus 5 and Pixel 6a. I understand that most U.S. banking apps work on Graphene. As far as contactless payments, try a Pixel watch. I understand that it is entirely separate from the phone.

Provisioning payment cards on your watch without being able to run the phone app will be quite a challenge, however!

I have never tried this, as I am happier with RFID on my individual credit cards.

However, Google Pay will certainly run on my Lineage OnePlus 5. It will not provision localhost, but I am guessing that it will provision a watch.

I would go buy the parts and try it just to know, but I doubt interest would remain here by the time I assembled everything.

Edit: Graphene has a page on this subject, and Garmin appears to be the best option.

https://discuss.grapheneos.org/d/1040-compatibility-with-sma...

Re: Google confirms Android attacks; no fix for most Samsung users

#107

Earlier quoted context omitted.

Again, no sympathy as that’s the route they chose. Rely on Google for everything OS and make a phone whereas Apple made a phone and supplied an OS. Apple made a product. Google made a software revenue stream. Entirely different things and now the Android makers are crying foul that they too have to do product engineering support. Nah. This is what you get when you rely on out of house innovation. I hope they all clos…

Yeah, and I also hope that all the PC makers close up shop as well. They rely on Microsoft for everything OS. Listen, you can just enjoy your iPhone in peace. Let other people make things, even if you feel they don't meet your standards.

They don’t rely on Microsoft, quite the contrary. The OEM/ISV vendor relationship at Microsoft is the backbone of the company. Linux, servers, phones, infotainment, TV’s, robotics, all run a flavor of Unix (Linux being the primary, but BSD is in there).

For the consumer PC market, Microsoft cornered the market early on with IBM and HP with DOS. They then tried to pull the ladder and raise the gates when they went against OS/2 and Amiga. To win the Windows for Networks wars.

The only reason why majority of consumers use windows is because that’s how they want it. You can easily build a PC, no Microsoft Windows anywhere in a 1 km radius, and install Linux or BSD flavor of choice and be 90% there. Companies don’t want you to do that (i.e. Microsoft and Apple) so they preinstall the OS and it updates over the Internet whenever it wants to. Installing whatever it wants to. User choice be damned.

No, Pc’s don’t need Microsoft anymore than Rap needs p.diddy

Re: Google confirms Android attacks; no fix for most Samsung users

#108
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

Just because one layer of the security stack is compromised doesn't turn your device into a paperweight. I know many people who use out-of-support and vulnerable devices and I am not aware of a single one getting pwned by a system exploit, it is always some kind of phishing or scam. This is anecdotal evidence but I couldn't find actual data, as most don't distinguish between malware that rely on system-level vulnerabilities (as in 0-day) and the ones that don't (like fake apps that steal credentials, mine crypto or inject ads). But it is clear that the former are a minority on Android.

If you don't know what to do with it because your security standards are so high, just give it to someone with lower standards then you, or use it for some project that doesn't involve sensitive data. And if security is broken to the core, there is probably some vulnerability you can exploit to root your phone and do whatever you want with it, including installing a custom ROM.

Still, I agree with you on making it mandatory to provide an unlock method, at least for out-of-support phones.

Re: Google confirms Android attacks; no fix for most Samsung users

#109
post #73

Earlier quoted context omitted.

I vote to just change the spelling to what almost everyone already thinks it is anyways. It'll still be just as weird. But "chs" is just nonsensical . The idea that it would sound like "sh" is baffling. I mean, I know this is English spelling which is not known for its regularity, but this is just too much.

> But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling In the word "french" C H is pronounced sh and nobody bats an eye, I don't think it's that outlandish that someone once read it as fuch-sia, incorrectly splitting it compared to the original. In the language French, fuchsia is unequivocally read something more like few-shia, and I'd bet that even though it comes from German Fuchs-ia (f…

Damn, I always thought Fuchsia is just a colour, but today I learned

  - Fuchsia is a flower
  - which is named after a German botanist (Leonhart Fuchs)
  - Fuchsia in English is pronounced completely different than in German. 
  - Google is surprisingly bad at naming their products

Re: Google confirms Android attacks; no fix for most Samsung users

#110
post #95

Earlier quoted context omitted.

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

Pixel 6a used to show a September patch as the latest, but tapping "check for updates" found a new one. As mentioned in other comments here, apparently tapping those buttons twice may help.

Can confirm on a Pixel 6a.

Says September is the latest system update. Click check updates, says it's up to date, click check updates again, says it's preparing system update and hangs out for a while - then says it's downloading and installing a 781M update.

WTF?

Update: OK finally the update completes an hour later, even the reboot took longer than usual - says it's "updated to December 5, 2025"

This phone running Android 16 for a bit over a month now.

Post reply on HN