Alena Zburnikova’s Post

View profile for Alena Zburnikova, graphic

Cyber Security Analyst | GPCS | GCLD | CompTIA Sec+ | CrowdStrike | Splunk | QRadar | Sentinel One | Jira | GIAC Advisory Board

I've learned a new term: n-days Google: Android patch gap makes n-days as dangerous as zero-days An n-day vulnerability is one that is publicly known with or without a patch. For example, if a bug is known in Android before Google, it is called a zero-day. However, once Google learns about it, it becomes an n-day, with the n reflecting the number of days since it became publicly known. Google warns that attackers can use n-days to attack unpatched devices for months, using known exploitation methods or devising their own, despite a patch already being made available by Google or another vendor. This is caused by patch gaps, where Google or another vendor fixes a bug, but it takes months for a device manufacturer to roll it out in their own versions of Android. The problem stems from the complexity of the Android ecosystem, involving several steps between the upstream vendor (Google) and the downstream manufacturer (phone manufacturers), significant discrepancies in security update intervals between different device models, short support periods, responsibility mixups, and others issues. https://lnkd.in/eQJ9337B

Google: Android patch gap makes n-days as dangerous as zero-days

Google: Android patch gap makes n-days as dangerous as zero-days

bleepingcomputer.com

Chris Vickroy

CompTIA Security + | Risk Management | Cyber Security Analyst | Splunk | CrowdStrike | Sentinel One | IBM QRadar

1y

You’re going to have to start teaching cybersecurity, I’m always learning a bunch from you.

To view or add a comment, sign in

Explore topics