Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
Google Android Security

Google Shifts Android Security Updates To Risk-Based Triage System (androidauthority.com) 2

Google has restructured Android's decade-old monthly security update process into a "Risk-Based Update System" that separates high-priority patches from routine fixes. Monthly bulletins now contain only vulnerabilities under active exploitation or in known exploit chains -- explaining July 2025's unprecedented zero-CVE bulletin -- while most patches accumulate for quarterly releases.

The September 2025 bulletin contained 119 vulnerabilities compared to zero in July and six in August. The change reduces OEM workload for monthly updates but extends the private bulletin lead time from 30 days to several months for quarterly releases. The company no longer releases monthly security update source code, limiting custom ROM development to quarterly cycles.
This discussion has been archived. No new comments can be posted.

Google Shifts Android Security Updates To Risk-Based Triage System

Comments Filter:
  • by Anonymous Coward on Monday September 15, 2025 @10:55AM (#65660626)

    The business reasons behind this decision notwithstanding, Google hates custom ROMs.

    I'm sure pushing source code releases to quarterly and hindering ROM development is only seen as a benefit on their side.

    The recent decision to start severely limiting sideloading and for all apps to be verified by Google indicates the writing is on the wall. The days of a more open Android OS are coming to a close.

    • I was 100% C=64 before I transitioned to Apple ][ before I went IBM-PC DOS, briefly Windows/OS2 Warp, then MacOS, then 100% linux, and added Android later.

      (sprinkle in some brief CP/M, BeOS, and NetBSD sidequests)

      I'll deal with the shift to the next phone platform OK, I think.

      I should probably dust off my Pine64 and try the latest builds again. It's been a few years since they were unusable as a daily driver.

      Folks, this might be a huge opportunity if you correctly pick the successor and are the first develo

To be or not to be, that is the bottom line.

Working...