9 ms·
Google confirms Android attacks; no fix for most Samsung users
- Squeeze2664 10mo agoIs GrapheneOS affected?
- jackwilsdon 10mo agoFrom what I can tell, if you're running the latest security preview release[1] then it's already fixed: https://grapheneos.org/releases#2025120400 https://grapheneos.org/releases#2025120400 [1]: https://discuss.grapheneos.org/d/27068-grapheneos-security-preview-releases https://discuss.grapheneos.org/d/27068-grapheneos-security-p...
- deleted 10mo ago[deleted]
- bramhaag 10mo agoGrapheneOS has patched this CVE back in September, as long as you've opted into the security preview releases: https://grapheneos.social/@GrapheneOS/115647360248469626 https://grapheneos.social/@GrapheneOS/115647360248469626
- purplehat_ 10mo ago[dead]
- pogue 10mo agoSo it sounds like if you don't sideload apps you would not be at risk, correct?
- gpm 10mo agoI suspect the average person who installs apps outside of the play store is still much more likely to be infected via malware that dodged the playstore's detection than the apps they install from other sources, because there's usually considerable trust involved with the other sources. In particular they're usually f-droid and open source apps compiled by f-droid.
- nutjob2 10mo ago> The Forbes link unfortunately doesn't say much about how it works. True, it says almost nothing of value about the exploit, but it does teach us that 30% is almost one in three.
- 4ndrewl 10mo agoConveniently Google can use this to justify banning installs from unofficial stores.
- da_grift_shift 10mo agoIs this guy going to make a slop repo for every new CVE in a high-profile product advisory so he can rack up some stars and put this shit on his resume? Jesus fuck. This is just polluting the namespace and making it harder for blue teamers and incident responders to share IOCs. His repos either lack a PoC and just contain a README with more emojis than facts; try to pass a public version checker off as a PoC; or invent a non-working PoC in the absence of technical details. Bullshit asymmetry.
- charcircuit 10mo agoThis isn't accurate and is just an AI hallucination.
- barrkel 10mo agoLook here: https://vulert.com/vuln-db/CVE-2025-48633 https://vulert.com/vuln-db/CVE-2025-48633 It has to do with setting the device owner, and gaining those powers; enabling / disabling apps, remote wipe, etc.. It's a local privilege escalation attack and doesn't require user interaction.
- weberer 10mo agoWhat did you use to make that chart? It looks really nice. Its the first time I've see these ASCII boxes on HN without gaps in the border.
- domoregood 10mo agohttps://archive.is/krzUC https://archive.is/krzUC
- xnx 10mo agoNo fix yet for Samsung. Being reliant on the hardware manufacturer (or network operator?) for OS updates is the crazy world we live in.
- ChocolateGod 10mo agoI hoped with a move to Fuschia, Google would attempt to fix this, but unfortunately Fuschia on mobile is dead.
- shwaj 10mo agoIt’s “Fuchsia” with a “chs” not a “sch”. Where do you get your information that it’s dead?
- jcranmer 10mo agoAs Randall Munroe pointed out in https://blog.xkcd.com/2010/05/03/color-survey-results/ https://blog.xkcd.com/2010/05/03/color-survey-results/, almost nobody knows how to spell "fuchsia" correctly. I only remember it by the mnemonic of it's fuck, but with an s.
- crazygringo 10mo agoI vote to just change the spelling to what almost everyone already thinks it is anyways. It'll still be just as weird. But "chs" is just nonsensical. The idea that it would sound like "sh" is baffling. I mean, I know this is English spelling which is not known for its regularity, but this is just too much.
- pwdisswordfishy 10mo agoIt comes from the surname of a German botanist. Which just happens to mean "fox". Never had problems with it. It would probably help if you pronounced it right, with a /ks/.
- baal80spam 10mo agoThis requires user action, right? User needs to install the APK by hand? In other words - if I don't install any crap on my phone I am safe?
- bigbadfeline 10mo ago> if I don't install any crap on my phone I am safe? We don't know. Practically no technical information is released about the bug, for what I care any play store app may exploit this at one time or another and there's no way to know. It's not like everyone and their CFO are shy of exploiting any user data they can get their greedy hands on.
- ActorNightly 10mo agoCVE records are public. All info is there.
- pajko 10mo agoBoth mentioned CVEs seem to be about local privilege escalation. So basically yes, if you don't install crap apps, there's a high chance that you are protected. Problem is that it might not seem to be a crap app, but a nice-looking game, etc. Also an attack can come in with an update of any app you have already installed on your phone.
- ajross 10mo agoThe point was surely more that apps being exploited via the Play Store can be mitigated there without client OS updates. The only hole here requiring the update needs a sideloaded attack.
- array_key_first 10mo agoExcept the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.
- rew0rk 10mo agoWhile the information leakage/disclosure is a big issue, It feels like its still a big jump to get users to install off-Play Store APKs?
- timothyduong 10mo agoConsidering there was a whole hubbub starting from late Aug 2025 RE: Certification of ALL Android apps/.apks: https://android-developers.googleblog.com/2025/08/elevating-android-security.html?m=1 https://android-developers.googleblog.com/2025/08/elevating-... Followed by a partial walk-back from Google in mid Nov 2025: https://android-developers.googleblog.com/2025/11/android-developer-verification-early.html https://android-developers.googleblog.com/2025/11/android-de... I would say there is a substantial amount of users willing to install off-play Store .APKs. Substantial enough they're also willing to take a 'jump' and accept the risks/errors displayed
- kelnos 10mo ago> This [update] was rushed out to all Pixel users. Pixel 8 here, still don't have the update. That's... not great.
- nervysnail 10mo agoI'd suggest you to use GrapheneOS.
- Cantinflas 10mo agoIs the patch already available for GrapheneOS?
- aussieguy1234 10mo agoAccording to above comments, it was added 3 days ago. I'm updating to the latest release now.
- subscribed 10mo agoIt was made available in the end of OCTOBER in the special security preview channel. GoS has already deployed patches to some of the vulnerabilities you'll read about in January. All the partnering vendors have access to the same bulletins. Multi-billion companies like Samsung or Google had access to that since AT LEAST October. They chose to release these patches late. Some will release these patches months form now. Some, perhaps never. So, the tiny team wins.
- fluidcruft 10mo agoHow quickly did GrapheneOS roll out the update?
- throawayonthe 10mo agoThree days ago. https://grapheneos.org/releases#2025120400 https://grapheneos.org/releases#2025120400 https://github.com/GrapheneOS/platform_manifest/releases/tag/2025120400 https://github.com/GrapheneOS/platform_manifest/releases/tag... https://grapheneos.social/@GrapheneOS/115666650605430196 https://grapheneos.social/@GrapheneOS/115666650605430196 not sure how soon it made it to a majority of devices, but i do have it rn EDIT: I was wrong, it's actually first mentioned in https://grapheneos.org/releases#2025102200 https://grapheneos.org/releases#2025102200 oct 22? https://github.com/GrapheneOS/platform_manifest/releases/tag/2025102200 https://github.com/GrapheneOS/platform_manifest/releases/tag...
- baaron 10mo agoMy tinfoil hat might be on too tight again... but the timing of this exploit coinciding with Google's full court press on Android user rights is just a little suspect. Especially after the ongoing public education campaign about the evils of "sideloading" an Android application.
- charcircuit 10mo ago>But in reality, Samsung (and the other Android OEMs) cannot compete with Google and its unique control over hardware and software. Yes, they can. We are talking about applying provided security patches to source code, and then releasing a new version of their OS. For patches that have existed for months. The time from patch to release should be on the order l of days from receiving the patches to having a validated OS release with the fix being sent to users. It's not the control of Android which makes Google possible to patch their Pixel branch of AOSP faster than Samsung can patch their own. It's that Samsung doesn't care about prompt security fixes so they don't allocate engineers to do the work.
- kwanbix 10mo agoThe problem is that each OEM releases 50 different models per year, vs Google (or Apple) that release 3 or 4 models.
- shiandow 10mo agoIf that truly is an issue then Android is a fundamentally broken OS. How many different models of PCs get released? How hard is it to patch any of their OSs?
- reactordev 10mo ago>How many different models of PCs get released? If you want to go that route, each manufacturer is responsible for their own drivers for windows, linux, and possibly Mac (though if it’s novel enough, they will do it). Then think about the components that make up a PC. Motherboard, CPU, Memory Control, IO, OS, Audio, Video. Each of those needs to release patches. So its orders of magnitude more than any Android OS. It’s just pure laziness on the hardware manufacturers that don’t want to invest in software/support. They want Google to do that.
- deleted 10mo ago[deleted]
- 10mo ago
- resist_futility 10mo agonice list of vulnerabilities and source changes https://source.android.com/docs/security/bulletin/2025-12-01 https://source.android.com/docs/security/bulletin/2025-12-01
- interloxia 10mo agoCVE-2025-54957 critical rce in Dolby audio processing is a worry. https://source.android.com/docs/security/bulletin/pixel/2025-12-01 https://source.android.com/docs/security/bulletin/pixel/2025...
- deleted 10mo ago[deleted]
- deleted 10mo ago[deleted]
- RadiozRadioz 10mo agoI'm really struggling to find any concrete information about what this vulnerability actually is. Does anyone know where to look for a good summary?
- aleatorianator 10mo ago[dead]
- jfindper 10mo ago>[...] there is a possible way to launch activities from the background due to a permissions bypass. https://www.cve.org/CVERecord?id=CVE-2025-48572 https://www.cve.org/CVERecord?id=CVE-2025-48572 https://android.googlesource.com/platform/frameworks/base/+/e707f6600330691f9c67dc023c09f4cd2fc59192%5E%21/#F0 https://android.googlesource.com/platform/frameworks/base/+/... https://android.googlesource.com/platform/frameworks/base/+/e707f6600330691f9c67dc023c09f4cd2fc59192%5E%21/#F1 https://android.googlesource.com/platform/frameworks/base/+/... >"In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed." https://www.cve.org/CVERecord?id=CVE-2025-48633 https://www.cve.org/CVERecord?id=CVE-2025-48633 https://android.googlesource.com/platform/frameworks/base/+/d00bcda9f42dcf272d329e9bf9298f32af732f93%5E%21/#F0 https://android.googlesource.com/platform/frameworks/base/+/...
- ActorNightly 10mo agoSearch CVE numbers. https://www.cve.org/CVERecord?id=CVE-2025-48633 https://www.cve.org/CVERecord?id=CVE-2025-48633 Basically, just like most things these days, its all just local privilege escalation. This means that you have to install/run an app that has these exploits built in. Soif you usage profile doesn't include downloading apps from untrusted sources, you don't need to worry.
- skeaker 10mo agoIn other words, continue as normal: Don't install random crap you don't trust. That this is even newsworthy is kind of strange.
- ptx 10mo agoNever mind the December security patches, Samsung haven't even released the November patches yet, the ones for the critical severity RCE. Unless you have a "major flagship model" [1], because apparently only the richest users deserve to be secure. [1] https://security.samsungmobile.com/securityUpdate.smsb https://security.samsungmobile.com/securityUpdate.smsb
- JohnTHaller 10mo agoGoogle Pixel 7 and Pixel 7 Pro are still stuck on the October patches.
- defanor 10mo agoPixel 6a used to show a September patch as the latest, but tapping "check for updates" found a new one. As mentioned in other comments here, apparently tapping those buttons twice may help.
- cmurf 10mo agoCan confirm on a Pixel 6a. Says September is the latest system update. Click check updates, says it's up to date, click check updates again, says it's preparing system update and hangs out for a while - then says it's downloading and installing a 781M update. WTF? Update: OK finally the update completes an hour later, even the reboot took longer than usual - says it's "updated to December 5, 2025" This phone running Android 16 for a bit over a month now.
- JohnTHaller 10mo agoI was clicking "Check for Updates" every few hours. Finally started working a bit ago. Fun fact: Pixel 7 and Pixel 7 Pro didn't get a November update
- th3typh00n 10mo agoMy 7 is on the December one.
- BoppreH 10mo ago
- londons_explore 10mo ago> with attacks that can achieve “remote denial of service Denial of service doesn't sound so bad... Does a reboot of the device solve it?
- Noaidi 10mo agoI don't understand why Samsung, with all their money, does not make their own fork so it does not have to rely on Google. I guess that is how they get all their money though. I was inches away from buying a 25+ this week. Glad I did not. But I mean, why do we only have two choices of OS for phones (I did not include GrapheneOS because it not easily available for the normie)? That is what is ridiculous. And why, in the US, do I only get three choices of flagship phones when in Asia they have like twenty? I hate this third world country I am living in.
- yaro330 10mo agoThey do have their own fork, they just don't have any of the security infra that google does. So they "rely" on Google for that.
- knorker 10mo agoWhy anybody would buy a Samsung product at this point I don't understand. Every single Samsung product I've had to use is actively user hostile. Like a petty kind of hostile.
- morshu9001 10mo agoThey're cheap
- knorker 10mo agoIf the flaws were just about missing premium features, that'd be one thing. But it's not. It's petty and abusive. For example, you can't see (I think it was) heart rate if you have a Samsung smart watch, but don't have a Samsung phone. They've gone out of their way to just not provide that, if you instead have a Pixel phone. And you need like 5 gigantic apps installed to manage it. Why is it not just one single Samsung wear app? Because they are abusive.
- morshu9001 10mo agoI mean that people buy it cause it's cheap, not that it's a good idea. They don't even look at the rest. It's like an Altima. Personally have no reason to consider anything but an iPhone, even if it has to be used.
- TiredOfLife 10mo agoThey are the only ones that makes phones with usable stylus.
- magicalhippo 10mo agoI've been Samsung since S3, but recently picked up a cheap Motorola as a secondary. Been pretty satisfied with it, clearly not as fancy as the S23 I got, but decent enough. However they only get 2 years of Android updates, and I'm getting spammed by Motorola at least once a week of not more to install some silly game or whatnot. I've also not been terribly impressed by the UX changes Samsung has made recently, lots of questionable decisions there. What other decent options are out there?
- kaluga 10mo ago[dead]
- yaro330 10mo agoForbes as always top notch journalism, what does Samsung have to do with Google updates and why are they indirectly blamed for Samsung's slowness?..
- VortexLain 10mo agoClosely tieing hardware and software instead of using unified OS images like on desktop, together with play "integrity" lock-in are the reasons why there are no security updates and software freedom on the mobile.
- BXLE_1-1-BitIs1 10mo agoI choose not to install any banking app and do my banking in incognito mode so that any malefactor who somehow gets into my device can't see where I bank. Of course that leaves security in the hands of the browser.
- DANmode 10mo agoGood news, they’re expecting and ready for that burden!