4 ms·
No they always check the signature before applying the patch.
by shoota 15y ago
No they always check the signature before applying the patch.
- Domenic_S 15y agoCheck it against what? A pwned digest?
- shoota 15y agoUnless you're rooted the updates are checked with the public key to make sure they are signed with the correct private key. Unless Google lost their set of private keys it wouldn't be possible to modify the update. It's entirely possible there are other exploits but a modified update.zip is not a likely vector.