Google simply modified how Android apps examine your cellphone’s safety


android system security updates vs play system updates 2

Rita El Khoury / Android Authority

Add Android Authority on Google:

TL;DR

  • Google’s new Safety State libraries let apps examine the safety standing of particular person Android parts as an alternative of relying solely on the general safety patch stage.
  • Apps can even examine whether or not a safety replace is offered and prepared for set up, probably prompting customers earlier than they carry out delicate duties.
  • A cellphone can now be acknowledged as protected even when its total safety patch date hasn’t modified, so long as it has obtained the particular safety repair.

Till now, your Android cellphone’s safety patch stage and the date connected to it have served as a straightforward approach for apps and companies to examine whether or not your cellphone is updated. But it surely doesn’t at all times inform the entire story.

That’s as a result of Android can replace totally different elements of the OS individually. Some updates come straight from the cellphone maker, whereas different parts might be up to date via Google Play with out requiring a full system replace.

Google has now launched the secure variations of its AndroidX Safety State and Safety State Supplier libraries. These are primarily new instruments that may give your cellphone’s apps a extra detailed have a look at the safety state of your gadget.

For instance, an app can examine which safety fixes are already put in, what the newest out there fixes are, and whether or not an replace is ready to be put in in your specific cellphone.

Banking apps on Google Play Store

Hadlee Simons / Android Authority

An method like this can be helpful for apps the place safety is especially necessary, like banking apps.

For instance, a banking app may examine whether or not your cellphone has a selected safety repair earlier than permitting you to carry out a delicate perform. If an replace is already out there however hasn’t been put in, the app could possibly ask you to put in it as an alternative of merely not responding or saying that your cellphone isn’t updated.

Google additionally says apps can examine whether or not particular safety vulnerabilities, referred to as CVEs, have been fastened on a tool. For example, apps will be capable to confirm that crucial NFC or Bluetooth fixes are in place earlier than authorizing tap-to-pay or proximity information sharing.

In the meantime, cellphone makers may also be capable to present that they’ve fastened particular safety issues.

Typically a producer can add a selected safety repair to a cellphone with out altering its total safety patch date. With Android 17, OEMs can inform Android about these particular person fixes, and the brand new Safety State instruments could make that info out there to apps.

So, for instance, your cellphone would possibly nonetheless present an older total safety patch date though a selected safety vulnerability has already been fastened.

In the end, this isn’t one thing common Android customers such as you and me would instantly discover. Most of those adjustments will happen behind the scenes. Nevertheless, over time, apps may get a a lot clearer image of whether or not a cellphone is definitely protected with out counting on the safety patch date alone.

Thanks for being a part of our group. Learn our Remark Coverage earlier than posting.