Skip to main content

Google-commissioned security report paints a bleak picture of Android

Android 6.0 Marshmallow.
Image used with permission by copyright holder
The lack of fast updates across the Android ecosystem means that more than 80 percent of device owners are at risk to at least one critical vulnerability. That’s according to a study from the University of Cambridge, which was partially funded by Google.

The study shows that while Google can make the latest version of Android safe from all vulnerabilities, its inability to get the updates out to every Android phone in a timely fashion makes most of the ecosystem unsafe. Even being one or two patches behind could put smartphone owners at risk of vulnerabilities like Stagefright, which is capable of taking over devices and infecting them with malware.

android-device-security
Image used with permission by copyright holder

In the study, each mobile vendor was graded based on security with scores from 1 to 10. Nexus devices ranked the highest at 5.2, followed by LG at 4.0, and Motorola at 3.1. Samsung came in fourth at 2.1, followed by Sony, and finally, HTC.

Samsung and LG both confirmed plans to stick on course with Google’s monthly updates, but HTC claimed that goal was unrealistic due to carrier testing. AT&T and Verizon Wireless have both been accused of routinely pausing updates, and blocking certain features like Google Wallet on Android devices.

Having a phone that’s vulnerable to attack might sound terrifying, but most critical vulnerabilities can only be exploited if the user downloads or clicks on something that is laced with malware. That’s why malware attacks tend to only reach a few hundred or thousand devices. Of course, some serious bugs like Heartbleed and Stagefright do pose risks to more devices.

Naturally, Android device owners would much rather have a system that is 100-percent safe. Google is working with device partners and carriers to ensure updates, especially security patches, are delivered at a speedy rate. Things just don’t always go as planned.

Android’s rival iOS isn’t completely off the hook when it comes to vulnerabilities, either. The most recent panic in China happened only a week ago, when an old video player returned and took over iPhones. A week before that, Chinese developers Baidu and Tencent were both caught using a faulty version of Xcode, infecting iPhone owners in China with malware.

However, the main difference is that Apple can immediately shore up the vulnerability on every iPhone that supports the latest version of iOS (which is the vast majority of iPhones) with a software update. Google isn’t able to do that because it’s phones are made by third-party manufacturers, whose own User Interfaces often slow down the update process, and the carriers who support these phones dictate when updates pass to individual phones.

Editors' Recommendations

David Curry
Former Digital Trends Contributor
David has been writing about technology for several years, following the latest trends and covering the largest events. He is…
Google Pixel 9: news, rumored price, release date, and more
Front and rear profile of leaked Google Pixel 9 renders.

The Google Pixel 8 and Pixel 8 Pro are Google's latest and most powerful devices, but it won't be that way for long. Rumors of the Google Pixel 8a mean this pair of flagships will be supplanted as the latest Google phones fairly soon — but they'll be able to hold on to the title of "most powerful" for a little while longer. The Google Pixel 9 range, while definitely on the way, isn't due to arrive any time soon.

But when it does, it's sure to be a trio of blockbusters. Leaks for the Pixel 9 family have been trickling in at a steady pace, and it seems like Google is planning on making some big changes this time around. If leaks are correct, we expect a new look and some exciting new AI features that go beyond what we've seen before.

Read more
Google has a magical new way for you to control your Android phone
Holding the Google Pixel 8 Pro, showing its Home Screen.

You don’t need your hands to control your Android phone anymore. At Google I/O 2024, Google announced Project Gameface for Android, an incredible new accessibility feature that will let users control their devices with head movements and facial gestures.

There are 52 unique facial gestures supported. These include raising your eyebrow, opening your mouth, glancing in a certain direction, looking up, smiling, and more. Each gesture can be mapped to an action like pulling down the notification shade, going back to the previous app, opening the app drawer, or going back to home. Users can customize facial expressions, gesture sizes, cursor speed, and more.

Read more
Android 15 has a clever way to make notifications less annoying
The Lock Screen on the Google Pixel 8 Pro.

This year's Google I/O 2024 was kicked off with one of the rare keynotes where Android did not see most of the limelight. AI -- and more specifically, Gemini -- was the talk of the show, and even the Android section of the keynote was filled with all the intelligent features coming with Android 15. The second beta of Android 15 rolled out just a few hours after the keynote, and it brings many more features that weren't discussed onstage. One of them is "Adaptive Vibration," which seems exclusive to Pixel phones for now.

As the name suggests, Adaptive Vibration is designed to fine-tune the vibration strength of incoming notifications based on the environment or where your phone is located. Android Authority discovered the feature under the Sound & vibrations menu in Android 15 's settings.

Read more