Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.
For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.
> Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.
Aren't those back-ported for a while?