logoalt Hacker News

microtonaltoday at 4:16 PM1 replyview on HN

Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.


Replies

stymaartoday at 5:04 PM

> Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

Aren't those back-ported for a while?

show 1 reply