Anyone know when these security fixes will roll out? - OnePlus 5 Questions & Answers

I've just read this article https://www.theregister.co.uk/2019/08/06/qualcomm_android_patches/ and it seems we might be affected.
Can I assume we will get the security patch soon?
Alan

Related

[Q] Anybody lacking official updates lately?

I've noticed that I seem to be missing a few updates that I expected I'd be one of the first in line for as a Nexus 4 owner.
Firstly, the Master Key vulnerability fix doesn't seem to have reached my phone. At least, according to Bluebox security scanner
Secondly, I still have no visibility of the new Google Maps redesign
My phone is a generic operator free Nexus 4 running stock (custom kernel though). Anybody else still waiting, or have I fallen off the automatic updates conveyor belt so far?
Where are you from? App updates from Google reach different parts of the world at different times.
thisisgil said:
I've noticed that I seem to be missing a few updates that I expected I'd be one of the first in line for as a Nexus 4 owner.
Firstly, the Master Key vulnerability fix doesn't seem to have reached my phone. At least, according to Bluebox security scanner
Secondly, I still have no visibility of the new Google Maps redesign
My phone is a generic operator free Nexus 4 running stock (custom kernel though). Anybody else still waiting, or have I fallen off the automatic updates conveyor belt so far?
Click to expand...
Click to collapse
We are sailing in the same boat. Rooted with only custom recovery rest stock.
vanmarek said:
Where are you from? App updates from Google reach different parts of the world at different times.
Click to expand...
Click to collapse
Based in the UK. If you've had the vulnerability patch already, did it come in the form of an app download or an ota update?
I'm in the UK and had the Maps update the day it was released.
thisisgil said:
Based in the UK. If you've had the vulnerability patch already, did it come in the form of an app download or an ota update?
Click to expand...
Click to collapse
Google hasn't released a patch for the vulnerability that's why you haven't gotten it. All they have done so far is release the code to their OEM's so they can patch their individual versions of Android. More than likely Nexus devices will get the patch in the 4.2.3 OTA whenever it gets released. In teh mean time their is an app in the Playstore, ReKey, that will address the vulnerability. Or you could just turn off install apps from unknown sources in the security settings which will also take care of the issue temporarily.
As for the other app updates they can take up to 2 weeks to deploy to all phones.

security patch

Hi, did anyone recieve march 18. security patch yet? Samsung and BlackBerry devices are receiving April 2. patch and we are still sucking with march 1. update.. Can anyone tell me what is going on?
They're different devices, they're on completely different update schedules. The patch they're receiving is probably actually months old by now.
nope, they are receiving april 2. patch from Google..
Source please?
This is being reported on crackberry with 2nd April security patch. However, that doesn't mean much other than the security for a particular phone, and it is a very particular phone that is still on lollipop.
I'd say this is a little bit of conflation and the fact of lollipop and BB's locked out kernel, bootloader and security makes it a nonstarter in terms of Nexus lines.

Is the OP2 vulnerable to CVE-2016-2060?

The vulnerability is officially recognized by Google here.
Can anyone confirm if it affects the OP2? And if it does, how to fix it or when will it be fixed by OP?
I don't think that vulnerability is fixed. Google fixed it now, Oneplus will take time.

I heard Verizon's Pixel Got a Software update yesterday Sept security patch

I hear Verizon and Google have released a ota of the Sept security patch for Verizon's pixels yesterday.. if you have a Verizon be sure to check for update manually in settings, about phone, software update..
I saw it on my Pixel XL this morning but not on my wife's Pixel. I have no details except the size of ~55MB since that is all that shows. It is not available for download in the OTA images or the factory images section. I assume it will not work over the standard OTA mechanism since the phones are rooted, and I have no interest in taking the patch blindly anyways.
The september 2017 Security Patch should have been released already. But due to some reasons, Google has delayed the upcoming monthly security update. The reason for the delay could be the release of a new stable Android 8.0.0 Oreo firmware update for Google Pixel and Nexus phone. Under the AOSP project, Google released 3 sets of monthly updates. One for the latest Android 8.0 Oreo, another for 7.1 Nougat, and finally the Marshmallow. Today, the Google Pixel XL device is receiving the September 2017 security patch OTA.
The first Google devices to receive the September 2017 Security Patch are the Unlocked Pixel XL 128 GB on AT&T and Verizon. That means, the US carriers shall receive the OTA update before the global roll out. The international variant of Pixel, Pixel XL, Nexus 6P, and Nexus 5X may receive the next security patch as soon as today. So stay tuned as we will list the update here.
The OTA update for AT&T Pixel XL brings the firmware build number OPR3.170623.007 dated September 5th 2017 level based on Android 8.0.0 Oreo. This an upgrade over the previous OPR6.170623.012 August 5th 2017 8.0.0 Patch.
This September OTA update comes in a very small OTA package. It weight about 50.61 MB in size. The changelog states the following.
This update fixes critical bugs and improves the performance and stability of your Pixel XL. If you download updates over the cellular network or while roaming, additional charges may apply. Update size 50.6 MB
Note: Google Pixel XL users have reported that the OTA notification shows that it is based on Android 7.1.2 Nougat, whereas the Pixel devices are already running 8.0.0 Oreo. However, upon update, the Android version is based on 8.0.0 Oreo and September 2017 security patch level. So it could be an error from Google’s side.
Download Google Pixel (XL) September 2017 Security Patch OTA update
One of the users for Google Pixel XL have managed to capture the latest OTA update from the LogCat file. September 2017 security patch.
AT&T Google Pixel XL 128 GB | OTA Download | google_marlin_marlin
Verizon carrier Pixel XL | OTA download |
8.0.0/OPR3.170623.007 from 8.0.0/OPR6.170623.012
Android 8.0 – Oreo for Pixel XL
Official factory images
Official full OTA images
Build for Global, Bell, Telus, Telstra, TMoUS, Sprint, USCC, Rogers/Fido
Android 8.0 – Oreo for Pixel
Official factory images
Official full OTA images
Build for Global, Bell, Telus, Telstra, TMoUS, Sprint, USCC, Rogers/Fido
Soon the official factory images for September 2017 Security Patch will show up. Also, download OTA update image from above and install it via ADB sideload method.
What's in the security patch
There are 30 issues resolved in the security patch dated 2017-09-01 and 51 in the 2017-09-05 one. Google notes that the two security patch level strings provide “Android partners with the flexibility to more quickly fix a subset of vulnerabilities that are similar across all Android devices.”
Google devices will receive the latter patch, while devices from other manufacturers will also feature OEM-specific fixes. This month’s bulletin also includes a new section that lists patches that are specific to Google devices.
Vulnerabilities range from moderate to critical, with the most severe possibly enabling remote code execution when browsing, using email, or MMS. However, Google notes that there are no reports of customers being affected by these security issues.
Still not interested? Some people are willing to give up root for a little while in order to improve their security... Only someone who thinks having root 24/7 is better than improving security is something different.. I know with this patch it stops people from remotely controlling you're device... I think if I was rooted I'd unroot and add this security protection...
Pixelxluser said:
Still not interested? Some people are willing to give up root for a little while in order to improve their security... Only someone who thinks having root 24/7 is better than improving security is something different.. I know with this patch it stops people from remotely controlling you're device... I think if I was rooted I'd unroot and add this security protection...
Click to expand...
Click to collapse
If someone is rooting, why not apply the update and reroot. We all do that every month. I just did mine for this update. I get the loss of security if you root but you dont need to give up root to update.
Pixelxluser said:
The first Google devices to receive the September 2017 Security Patch are the Unlocked Pixel XL 128 GB on AT&T and Verizon. That means, the US carriers shall receive the OTA update before the global roll out.
The OTA update for AT&T Pixel XL brings the firmware build number OPR3.170623.007 dated September 5th 2017 level based on Android 8.0.0 Oreo. This an upgrade over the previous OPR6.170623.012 August 5th 2017 8.0.0 Patch.
AT&T Google Pixel XL 128 GB | OTA Download | google_marlin_marlin
Click to expand...
Click to collapse
I would like to know where you copied & pasted this info since at&t does not sell the pixel, so, I can't see them releasing a ota.
Last I knew, google controls this
Sent from my Pixel using XDA-Developers Legacy app
I was rooted on Oreo and updated to this new build and my service still sucks? I'm right next to a cell tower and my phone is going from -64 to -80dbm and its making my battery tank. I'm about to go back to 7.1.2.
I think a big misconception is trying to pull people away from improving their own security and safety by using the whole oh you will lose root if you do that and may lock you're bootloader.. just because you personally don't care about you're own safety doesn't mean you should try to prevent someone else from improving their own safety.. come on the fact is it's just root you will be fine to live without it for a little while it's not going to hurt you to give it up for a few...
And another thing is all the new pixels and Pixel XL are gonna come preinstalled with these new security patchs so you all might as well get used to it...
I don't understand why Google doesn't post these on their website immediately. I have a Pixel on Verizon and have no way of accessing it until they finally publish the update to their site or zi just start receiving it. It's always this awkward way with a lot if confusion. It would also be nice if they fixed the few small bugs in Oreo (i.e. picture in picture mode causing reboots when you turn the screen off/back on). It's just a little annoying.
The Sept security patch also fixes a Bluetooth problem. It's recommend to update to any software with Sept security patch and later security patch
Google is still working on getting the September security patches out the door, but it has posted a security bulletin detailing the changes. Several of the flaws noted in the bulletin are part of an enormous Bluetooth vulnerability discovered by Armis Labs, which bills itself as an IoT security firm. The "BlueBorne" attack exposes billions of Android devices to complete takeover by hackers, but it's not only Android. The same flaw exists in Windows, Linux, and some versions of iOS.
BlueBorne is dangerous because most devices have Bluetooth active even when it's not actively being used, and an attacker does not need to pair with the target device to completely take it over. There are eight vulnerabilities listed by Armis, four of which are critical (though Google's classifications differ). The most severe issues are the two remote code executions, which allow an attacker to completely own a device without the user even knowing. These flaws are present in the Bluetooth Network Encapsulation Protocol (BNEP) service, which is used for internet sharing and networking.
You don't even need an internet connection to infect a device, and the Android demo above is wild. If one of the affected devices has Bluetooth on, it's a target. The attacker can gain complete control of the phone to launch any app, install malware, and exfiltrate data. Armis estimates that about 8 billion devices are vulnerable, including 2 billion Android phones, tablets, set top boxes, and watches. There are another 2 billion Windows devices and around 1 billion iOS phones and tablets affected. BlueBorne doesn't work on iOS 10, so the damage is mitigated there.
BlueBorne vulnerabilities in the security bulletin
Most of the vulnerabilities in Android reported by Armis affect all recent builds of the OS, so Google is adding a lot of patches to AOSP. It's up to OEMs to push those out to devices, though. Anything with a patch level of September 1st, 2017 or later will have the necessary fixes. It's going to take time for this patch to roll out, and in the meantime, there are a lot of vulnerable devices.
This was took from Android polices website
It's also recommend that the devs here on xda get rid of the software which is vuneralable to theses problems.. it doesn't really show good faith of a Dev if they know there's security problems in the roms but yet keep them posted for someone to download and install...
Pixelxluser said:
It's also recommend that the devs here on xda get rid of the software which is vuneralable to theses problems.. it doesn't really show good faith of a Dev if they know there's security problems in the roms but yet keep them posted for someone to download and install...
Click to expand...
Click to collapse
Boring.......
Pixelxluser said:
It's also recommend that the devs here on xda get rid of the software which is vuneralable to theses problems.. it doesn't really show good faith of a Dev if they know there's security problems in the roms but yet keep them posted for someone to download and install...
Click to expand...
Click to collapse
Do you even know what the ... ah not worth it
Sent from my Pixel using XDA-Developers Legacy app

KRACK Attack Vulnerability

In recent news, a new vulnerability came to light that affects Wifi on OS's like Windows, Linux, and more specifically: Android 6.0 and higher
https://www.krackattacks.com/
Just wanted to put it out, because this could most likely also affect our devices.
It seems like there are already patches/software updates rolling out.
What are your thoughts?
(Might be in the wrong place, feel free to move this post)
The official ROM still runs September 1st 2016 security patch, I doubt we will ever see the november 2017 patch that will fix this

Categories

Resources