I'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?
Search CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.
Google confirms Android attacks; no fix for most Samsung users
131–140 of 177 posts
Re: Google confirms Android attacks; no fix for most Samsung users
#132Earlier quoted context omitted.
We have an OS security update that is only release to users of a specific hardware, once approved by their mobile operator. It may be added to vendor-specific OS versions some time later (weeks, month or never). The vendor-specific may not be approved by a telco if the vendor doesn't have a relationship with that telco. Now think that millions of people use the same OS on many different flavours, on different hardwar…
I never understood why a mobile operator has any say in when to apply security patches? Does it happen with iPhones?
It’s gotten slightly more confusing with the major updates now being optional. You get a choice between getting a feature update or just security patches. Unless I missed it, my phone never really asked me to update to the latest iOS 26. But I can, it’s there. I’m instead on the latest version of iOS 18. (They changed number schemes. 18 is last years major update)
Apple also does security updates for quite a long time. iOS 15, from 2021, got a security patch in September of this year, and works on the iPhone 6s from 2015.
Re: Google confirms Android attacks; no fix for most Samsung users
#133Earlier quoted context omitted.
The beginning of the English word "fuchsia" is not pronounced like the German word Fuchs, so indeed the spelling does not match the pronunciation. This is independent of the fact that it comes from that word. Plenty of things in English (and, in fact, loanwords in every language) sound different from the words they're derived from; that doesn't mean trying to imitate the source language is the "right" pronunciation.…
> If you pronounce fuchsia like "fuksia" nobody will understand you. TIL and yet another case of "English is fucking weird".
Re: Google confirms Android attacks; no fix for most Samsung users
#134Earlier quoted context omitted.
Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.
Pixel 6a used to show a September patch as the latest, but tapping "check for updates" found a new one. As mentioned in other comments here, apparently tapping those buttons twice may help.
Fun fact: Pixel 7 and Pixel 7 Pro didn't get a November update
Re: Google confirms Android attacks; no fix for most Samsung users
#135Earlier quoted context omitted.
I'd suggest you to use GrapheneOS.
How quickly did GrapheneOS roll out the update?
Re: Google confirms Android attacks; no fix for most Samsung users
#136Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb
Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.
Re: Google confirms Android attacks; no fix for most Samsung users
#137Earlier quoted context omitted.
Why would you want security, if you get 'play integrity' for phones that received no updates since 2 years. Google's current security practices are more than dubious IMHO. Now they are not releasing any source for security patches for 3 month, to 'protect' vendors that are too slow updating. As if there is no chance for bad actors to reverse engineer those patch sets.
I have the strongest level of "Play Integrity" on a Xiaomi phone that hasn't received any updates since the beginning of 2020. Google Pay and co work fine. It makes sense when you remember that PI is not about security at all, that's just an excuse.
Re: Google confirms Android attacks; no fix for most Samsung users
#138Why anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.
Re: Google confirms Android attacks; no fix for most Samsung users
#139Earlier quoted context omitted.
Are apples drivers open source?
No. Which is why "the only exception is macOS" is also false. At some point Apple drops support for that model and then that hardware not only gets no more driver updates, because the whole system is tied to the rest of it, it gets no more updates at all. So the only exception is systems with open source drivers. Those are basically supported as long as the hardware architecture is and enthusiasts even have the optio…
If you want fast responses to driver bugs, you only have Apple or a fully open-source Linux systems as an option.
Re: Google confirms Android attacks; no fix for most Samsung users
#140Why anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.