Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

171–177 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#171

Earlier quoted context omitted.

Search CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.

In other words, if you ever need to install anything on your device, you do need to worry. What even could be trusted, a random app from Play Store?

> In other words, if you ever need to install anything on your device, you do need to worry.

No, its "If you ever need to install some random app from the play, you do need to worry"

I installed the Teams app and Torque Pro today. I am not worried. I've also got the Sherlock games (purchased way back when) that I have yet to install on my new phone.

Installing that app also will not worry me. These apps are trusted because of the authors, not because of the Play store.

Worry is not binary, it's a probability, and you are at high risk if you're installing every rando's app on your phone and low risk if you are not.

Re: Google confirms Android attacks; no fix for most Samsung users

#172
post #144

Earlier quoted context omitted.

I can't see how the situation with apple is any better considering what you've said, you're still beholden to apple to provide a fix. Even if that fix might be quicker coming IF apple is currently supporting the device; not at all otherwise.

> I can't see how the situation with apple is any better Because in the Windows world, there often are no updates after maybe 1, 2 years. Chances are high, if you look in Device Manager of any reasonably new system, you'll find a lot of drivers dating back to before Covid and that's 5 years ago. Chances are even higher that if you look close enough, you'll find something being exploitable. With Apple? Their track rec…

Let's concede that Windows sucks.

If you have macOS, it's supported until the OEM (Apple) stops supporting it. If you have Linux with some proprietary driver, it's supported until the OEM (e.g. Nvidia) stops supporting it. If you have Linux with open source drivers, it keeps working pretty much indefinitely.

Meanwhile 10+ year old hardware is serviceable for many uses. A 15 year old machine from the scrap heap could have 64GB of RAM, a different one could have a low idle power draw for a use where that's the only thing that matters. Put a cheap SSD in a machine of that vintage and someone who is just using web and email could keep using it for the rest of their life.

Re: Google confirms Android attacks; no fix for most Samsung users

#173
post #89
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Samsung for the longest time was releasing updates way too late, and what they were releasing monthly was old patches. Buying a device directly from Samsung may be different, but the manufacturer still has to usually convert the pure android update to their branch. Still, trying to find a pure android phone is important. More manufacturers used to make them. Example: https://www.androidauthority.com/best-smartphones-…

I thought Google was moving stuff out of the open source stock android branch and into their proprietary pixel development branch, such that the functionality of stock android has been diminishing to the point that a phone running stock android would be barely usable as the device we'd expect. Maybe I've read wrong and misunderstood though.

Re: Google confirms Android attacks; no fix for most Samsung users

#174

Earlier quoted context omitted.

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

The December updates for Pixel 7 and Pixel 7 Pro are available to manually download on Google's website [0], so the updates do exist, although Google might not be rolling them out to the general public quite yet. But the December update for Pixel 7a are completely missing from that website, and trying to update from the Settings app also shows no updates available. [0]: https://developers.google.com/android/ota

The 7a got a November update while the 7 and 7 Pro did not. Perhaps that's related to the delay.

Re: Google confirms Android attacks; no fix for most Samsung users

#175
post #167
post #116

Earlier quoted context omitted.

There are two kinds of people: 1. Those who can extrapolate from incomplete information

Please, feel free to extrapolate for me whether the "unspecified vulnerability" referenced in the article was introduced more or less than five years ago.

The point was the whole phone has been vulnerable to a multitude of RCEs for five years, so it doesn't really matter if its the latest exploit, its a silly request.

Re: Google confirms Android attacks; no fix for most Samsung users

#176
post #68

Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb

Google Pixel 7 and Pixel 7 Pro are still stuck on the October patches.

Specifically for 7a:

Rumor is the Pixel 7a December update rollout was paused due to a severe wifi bug. You might not want to upgrade manually at this time, even if you find images available for download.

(The rumor is somewhat weak, it's apparently everyone regurgitating one seemingly AI chat.. Google needs to state the reason publicly.)

Re: Google confirms Android attacks; no fix for most Samsung users

#177
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

I hoped with a move to Fuschia, Google would attempt to fix this, but unfortunately Fuschia on mobile is dead.

[dead]
Post reply on HN