Fresent LLC’s Post

View organization page for Fresent LLC, graphic

349 followers

#Google has published its annual 0-day vulnerability report, presenting in-the-wild exploitation stats from #2022 and highlighting a long-standing problem in the #Android platform that elevates the value and use of disclosed flaws for extended periods. More specifically, Google's report highlights the problem of n-days in Android functioning as 0-days for threat actors. . The problem stems from the complexity of the Android ecosystem, involving several steps between the upstream vendor (Google) and the downstream manufacturer (phone manufacturers), significant discrepancies in security update intervals between #different #device models, short support periods, responsibility mixups, and others issues. A _zero-day vulnerability_ is a software flaw known before a vendor becomes aware or fixes it, allowing it to be exploited in attacks before a patch is available. However, an _n-day vulnerability_ is one that is publicly known with or without a patch

Google: Android patch gap makes n-days as dangerous as zero-days

Google: Android patch gap makes n-days as dangerous as zero-days

pike.link

To view or add a comment, sign in

Explore topics