ZeroHour
Product

AndroidX Security State

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches

Google releases Android Security State libraries letting apps and enterprise tools verify component-level security patch status across system, Mainline modules, and kernel.

Google released stable AndroidX Security State 1.1.0 and Security State Provider 1.0.0 libraries that expose detailed device patch posture. Apps can query Device, Published, and Available patch levels for the Android system, Mainline modules, and LTS kernels, and can run vulnerability-specific checks for components like NFC and Bluetooth. The libraries integrate with Android Security Bulletin data via the Open Source Vulnerabilities database, and Android 17 adds Supplemental Patches XML so OEM backported fixes are recognized immediately.

Android apps can now check security patches down to individual device components

Google shipped stable AndroidX Security State libraries letting Android apps check per-component patch levels and CVE patch status via OSV data.

Security State v1.1.0 and Security State Provider v1.0.0 expose three patch levels per device component: installed (DSPL), published in Android Security Bulletins (PSPL), and available to download (ASPL), covering the OS, Play system modules, and the Linux kernel. Apps can verify specific CVE fixes, for example NFC or Bluetooth patches before enabling tap-to-pay, and the libraries integrate with the Open Source Vulnerabilities database for CVE-level auditing. Google Play system updates and GOTA already adopt the framework, and Android 17 lets manufacturers declare backported fixes beyond the stated patch level.

Help Net Securityupdated · 5h agofirst · 7h agoTools 2 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.