Skip to main content

Some Android manufacturers lie to customers about installing security updates

Your Android phone may not be as secure as you think it is. According to a recent report from German security firm Security Research Labs, which was first picked up by Wired, not only do many Android manufacturers not always keep up to date with Android security updates, but they actually lie to customers by telling them that their device has the latest patch installed.

It’s troubling news. In recent years, it appeared Android manufacturers were getting better at ensuring that their devices are safe and up to date — but it seems that may not be the case after all.

Recommended Videos

The researchers — Karsten Nohl and Jakob Lell — spent two years analyzing Android devices and checking their code to see if the manufacturers had actually installed the updates, or if they were instead simply claiming that they were up to date. What they found was that many devices had what they called a “patch gap,” where the phone’s software claimed the phones were up to date, but the code proved that often dozens of patches had simply been skipped.

Even worse is the fact that the lying seems to be a pretty common practice. The team tested firmware from a hefty 1,200 phones from the likes of Google, Samsung, HTC, Motorola, ZTE, and TCL, and found that even major releases from massive companies like Samsung occasionally skipped a security patch.

Some manufacturers were worse than others. While the likes of Sony and Samsung only skipped one or no security updates, Xiaomi, OnePlus, and Nokia skipped up to three. HTC, Huawei, LG, and Motorola skipped up to four, and TCL and ZTE skipped more than four. Phones built by Google did not skip security updates. According to SRL, the skipped patches could also be related to the chipset used by the phone. According to the company, phones with Samsung-built chips had very few skipped patches, while phones with MediaTek chipsets skipped a whopping 9.7 patches on average. This may be because bugs are found in the chip rather than the operating system, and the manufacturer then depends on the maker of the chipset to patch those bugs before a security update can be installed.

According to Google, which gave a statement to Wired for the report, one cause for the skipped updates could be that some devices are uncertified, meaning that they’re not held to the same security standard. On top of that, skipping patches could be because of a specific phone not offering the feature that needs to be patched in the first place.

Of course, it really doesn’t matter why manufacturers are skipping updates — what matters is that even when updates are skipped, the software still claims that the phone is up to date when it isn’t. In reality, it’s still extremely hard to hack an Android phone, and there are plenty of other security measures in place to prevent an attack — but the fact is that smartphone manufacturers are lying.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
These Samsung phones are at risk for a big security vulnerability
The Galaxy Note 20 Ultra in hand.

Samsung Semiconductor has confirmed that certain Samsung phones, as well as others, are vulnerable to a “privilege escalation” hack identified earlier this year by Google security researchers. This issue concerns older devices with the Exynos 9820, 9825, 980, 990, 850, and W920 chipsets.

Though Samsung didn’t indicate which handsets are affected, Tom’s Guide did, and the list includes some familiar devices. These include the Exynos 990-equipped Galaxy S20 series and Galaxy Note 20 and the Exynos 980-equipped Galaxy S10 series and Galaxy Note 10. Thankfully, if you purchased any of these phones in the U.S., they have Qualcomm Snapdragon chips installed and are not affected.

Read more
Android 16 might give its own spin to iPhone’s Dynamic Island alerts
The DynamicSpot Dynamic Island at the top of the Pixel 7 Pro.

Over the past few weeks, we’ve come across some interesting details about the next major build of Android. Currently in development under the apparent codename of Baklava, Android 16 will reportedly bring a cool new feature called Priority modes for notifications.

If that sounds familiar, that’s because Apple already offers a bunch of focus modes toward the same goal and bolsters the system with AI-assisted priority notifications in iOS 18. It seems Google doesn’t want to be left behind, and in doing so, could very well lift from a popular iPhone trick.

Read more
Android 15: everything you need to know
Android 15 easter egg shown on a Google Pixel 6a kept on a table in front of moon shaped lamp and pink flowers.

Google's next major update for smartphones is here. Android 15 rolled out to Pixel devices on October 15 and will trickle down to countless other devices over the next several months. Android 15 has eschewed visual updates and instead tidies up the interface and improves existing features. It also gets a number of under-the-hood improvements that you may toy with occasionally.

Android 15 packs a host of privacy-centric features, including the excellent new Private Space. Android 15 also brings a big boost to satellite communications, extending the functionality beyond the Pixel lineup. Let's dive into more details about the availability and new features coming to your phone with Android 15.
Android 15 release date

Read more