Live data from Hacker News

Google confirms Android attacks; no fix for most Samsung users

forbes.com

61–70 of 177 posts

Re: Google confirms Android attacks; no fix for most Samsung users

#61

I'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?

>[...] there is a possible way to launch activities from the background due to a permissions bypass.

https://www.cve.org/CVERecord?id=CVE-2025-48572

https://android.googlesource.com/platform/frameworks/base/+/...

https://android.googlesource.com/platform/frameworks/base/+/...

>"In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed."

https://www.cve.org/CVERecord?id=CVE-2025-48633

https://android.googlesource.com/platform/frameworks/base/+/...

Re: Google confirms Android attacks; no fix for most Samsung users

#62
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

I'd suggest you to use GrapheneOS.

How quickly did GrapheneOS roll out the update?

Re: Google confirms Android attacks; no fix for most Samsung users

#63
post #27
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

Just go to the software update, touch the button, then touch it a second time, and that will give you all available updates immediately, regardless of your random position in the rollout process.

I don't see it yet either and have mashed it a bunch (Pixel 7, T-Mobile). Says it's running October's update with no updates available.

Re: Google confirms Android attacks; no fix for most Samsung users

#64
post #27
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

Just go to the software update, touch the button, then touch it a second time, and that will give you all available updates immediately, regardless of your random position in the rollout process.

I had the same experience as peer comments. I'm on Pixel 8 and Google Fi. When I check for updates, I'm told I'm up-to-date with the last update being over a month old.

Re: Google confirms Android attacks; no fix for most Samsung users

#66

Earlier quoted context omitted.

I'd suggest you to use GrapheneOS.

How quickly did GrapheneOS roll out the update?

Three days ago.

https://grapheneos.org/releases#2025120400

https://github.com/GrapheneOS/platform_manifest/releases/tag...

https://grapheneos.social/@GrapheneOS/115666650605430196

not sure how soon it made it to a majority of devices, but i do have it rn

EDIT: I was wrong, it's actually first mentioned in https://grapheneos.org/releases#2025102200

oct 22? https://github.com/GrapheneOS/platform_manifest/releases/tag...

Re: Google confirms Android attacks; no fix for most Samsung users

#67
post #11

> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.

My friend is still on the Pixel 2. Are they affected?

Pixel 2 stopped getting updates almost 5 years ago

Re: Google confirms Android attacks; no fix for most Samsung users

#68
Never mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure.

[1] https://security.samsungmobile.com/securityUpdate.smsb

Re: Google confirms Android attacks; no fix for most Samsung users

#69
post #5

No fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.

> Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in. Being reliant on a single OS permanently nailed to the hardware is no less crazier. I'd like to be able to install another OS on a vulnerable device, it would help tremendously and not only with the security of that specific device. Now I've got some expensive paperweights that I can't even use as such be…

If you are buying now, you want a device on a v5 Linux kernel with BPF support, where the bootloader can be unlocked and VoLTE is implemented in the 3rd-party ROM.

LineageOS has a build roster of current devices at this URL:

https://lineageos.org/Changelog-30/

The Pixels are the most flexible, but don't buy a model from Verizon (they don't allow unlocked bootloaders).

Most other OEMs require you to generate an unlock token and send it to them, then wait a week, which is extrememly inconvenient (and sometimes they just stop and refuse, as I understand OnePlus has).

If you want a locked bootloader at the end of the process for security, then you will be on a later Pixel with Graphene.

Re: Google confirms Android attacks; no fix for most Samsung users

#70
post #55

This requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?

Both mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.

The point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.
Post reply on HN