Remix.run Logo
microtonal 5 hours ago

Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

For those not aware, Android Security Bulletins only cover high/critical vulnerabilities. There are also rumors that Google will soon stop fixing vulnerabilities in not-actual versions that were discovered by Google in LLM-driven vulnerability discovery. There was recently a GrapheneOS thread about it.

stymaar 4 hours ago | parent [-]

> Getting security updates for issues that are not marked high/critical. These are not your typical RCE, but they are used in exploit chains.

Aren't those back-ported for a while?

microtonal 4 hours ago | parent [-]

No, they are not.

https://grapheneos.social/@GrapheneOS/114101511604296440

You need new releases or QPRs to get other patches.