Smartphone Android Manufacturers Skipping Security Patches and Not Informing Users

Follow Us

Some Android phone vendors are skipping security patches without notifying users, and instead hoodwinking their customers into believing their smartphone software is up to date with Google’s monthly security releases, according to a new research. Researchers with Germany’s Security Research Labs (SRL) tested the firmware of 1,200 phones from manufacturers like Google, Samsung, Sony, Nokia, Huawei, Motorola, LG, HTC, ZTE and TCL for every patch released in 2017.

Android Manufacturers




The results they found were quite interesting. Researchers Karsten Nohl and Jakob Lell said that there's often a hidden “patch gap” between what the phones manufacturers tell the users about their software patch and what patches have actually been installed.

"Our large study of Android phones finds that most Android vendors regularly forget to include some patches, leaving parts of the ecosystem exposed to the underlying risks," the SRL report notes.

Google pushes out Android security updates each month that is a collection of patches for a variety of security bugs. But while manufacturers may install some of the fixes, changing the security update date to the latest, they can fail to install all the patches included in any particular month’s update.

Failing to update their smartphones with the latest security updates is one thing, but SRL found that many phone makers simply lied without installing any patches at all.

"We found several vendors that didn’t install a single patch but changed the patch date forward by several months," SRL founder Nohl said. For example, Samsung's 2016 J3 claimed to have every 2017 Android patch installed but in fact when 12 weren't actually installed.

Still, SRL says that major handset makers, Google, Samsung and Sony have the most secure Android phones missing on an average from zero to one update. Then there are companies like Nokia, OnePlus and Xiaomi which miss between one and three patches, while phones sold by HTC, Huawei, LG and Motorola are missing three to four patches. Bringing up the rear are ZTE and TCL, whose phones on average have missed more than four Android security patches.

In response, Security Research Labs has updated its SnoopSnitch app, where Android phone users can get an accurate breakdown of which security updates have and haven't been installed.

Recent Comments

Sujata :

They have improved a lot. Will keep improving in coming years as well.

BSNL 4G Feels a Tad Bit Late, but Still Impactful

Sujata :

2026 a asha kori, 4g 5g dutoi paabo, but tao kichu bola jai na, afterall it's bsnl.

BSNL 4G Feels a Tad Bit Late, but Still Impactful

Sujata :

You are right, airtel only deploys network from where they can generate revenue. Since 2023, I have seen 3 new…

BSNL 4G Feels a Tad Bit Late, but Still Impactful

Sujata :

Airtel is literally looting in 5G. so many issues with their so called unlimited 5g. Only 4G is best(In most…

BSNL 4G Feels a Tad Bit Late, but Still Impactful

TheAndroidFreak :

Nope, I was talking about 300GB per month and not unlimited data like Jio. Is Airtel copying from China operator?…

Can BSNL Make a Comeback Ever

Load More
Subscribe
Notify of
33 Comments
newest
oldest most voted
Inline Feedbacks
View all comments