Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

21–30 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#23
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

I hoped with a move to Fuschia, Google would attempt to fix this, but unfortunately Fuschia on mobile is dead.

It’s “Fuchsia” with a “chs” not a “sch”. Where do you get your information that it’s dead?

Re: Google confirms Android attacks; no fix for most Samsung users

#24

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

> if I don't install any crap on my phone I am safe?

We don't know. Practically no technical information is released about the bug, for what I care any play store app may exploit this at one time or another and there's no way to know. It's not like everyone and their CFO are shy of exploiting any user data they can get their greedy hands on.

Re: Google confirms Android attacks; no fix for most Samsung users

#25

[dead]

Look here: https://vulert.com/vuln-db/CVE-2025-48633

It has to do with setting the device owner, and gaining those powers; enabling / disabling apps, remote wipe, etc.. It's a local privilege escalation attack and doesn't require user interaction.

Re: Google confirms Android attacks; no fix for most Samsung users

#26
post #7

[dead]

So it sounds like if you don't sideload apps you would not be at risk, correct?

I suspect the average person who installs apps outside of the play store is still much more likely to be infected via malware that dodged the playstore's detection than the apps they install from other sources, because there's usually considerable trust involved with the other sources.

In particular they're usually f-droid and open source apps compiled by f-droid.

Re: Google confirms Android attacks; no fix for most Samsung users

#27
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

Just go to the software update, touch the button, then touch it a second time, and that will give you all available updates immediately, regardless of your random position in the rollout process.

Re: Google confirms Android attacks; no fix for most Samsung users

#29

>But in reality, Samsung (and the other Android OEMs) cannot compete with Google and its unique control over hardware and software. Yes, they can. We are talking about applying provided security patches to source code, and then releasing a new version of their OS. For patches that have existed for months. The time from patch to release should be on the order l of days from receiving the patches to having a validated…

The problem is that each OEM releases 50 different models per year, vs Google (or Apple) that release 3 or 4 models.

Re: Google confirms Android attacks; no fix for most Samsung users

#30
post #23

Earlier quoted context omitted.

I hoped with a move to Fuschia, Google would attempt to fix this, but unfortunately Fuschia on mobile is dead.

It’s “Fuchsia” with a “chs” not a “sch”. Where do you get your information that it’s dead?

As Randall Munroe pointed out in https://blog.xkcd.com/2010/05/03/color-survey-results/, almost nobody knows how to spell "fuchsia" correctly. I only remember it by the mnemonic of it's fuck, but with an s.
Post reply on HN