logoalt Hacker News

AJRFtoday at 9:59 AM6 repliesview on HN

Weird thing to see at number 3 on HN - is there some subtle context I am missing here?

Are we wink winking that it's a lot of fixes?


Replies

microtonaltoday at 11:54 AM

It is a lot of fixes and the Android Security Bulletins of June and Android 17 also had a lot of fixes [1], despite ASBs only containing high/critical vulnerabilities (other vulnerabilities are only fixed in major releases and QPRs, which most Android vendors respectively roll out late or never at all).

I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules).

[1] https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17

show 1 reply
DStiegotoday at 10:11 AM

Relevant context might be for example that there are 4 mentions each of Claude by Anthropic and XGPT by ThreatBook, both based on LLMs.

AI attribution might be one reason people are particularly curious.

show 1 reply
grahamleetoday at 10:28 AM

And it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).

show 1 reply
cromkatoday at 10:57 AM

I think it's because it's the first big batch of fixes found at Apple by Mythos.

show 1 reply
croemertoday at 10:10 AM

I think that's it?