Google Android security patch is required, attacks are underway, Samsung, Pixel

Regardless of what you call it only newer Android devices are affected, mostly 2022 models running Android 12 or later, which is really the only saving grace. So, that’s the good news. Does that mean you can relax if you, like most people, are using a phone from 2021 or earlier? Nope, sorry. While Dirty Pipe won’t impact you, the May security fix covers a whole bunch that will, including some high-severity vulnerabilities in the Android Framework component that could allow an escalation of privilege attack. Regardless of your Android device age, please apply the update as a matter of urgency. In all, some 36 vulnerabilities have been addressed in the May Android security update. Just to complicate matters a little, these are spread across two Android security updates from Google: the first dated May 1 and the second May 5.

If you are an Android user, regardless of your hardware manufacturer of choice, you should install the 36 vulnerability-fixing May security update as soon as possible. What’s the big deal? A high-severity vulnerability that was published in January and is still being abused in the field has now been addressed. It’s a Linux kernel vulnerability that the researcher who discovered it dubbed ‘Dirty Pipe.’ Actually, we dull and geeky security types refer to it more properly as CVE-2022-0847.


  • If you are a Samsung smartphone user then you don’t escape getting hit with the additional vulnerabilities stick I’m afraid. In all, some 18 vulnerabilities are fixed by this update, along with the Google patches. These vary in severity from low to high, at least those that have been disclosed do. Samsung also stated that some of the security vulnerabilities “cannot be disclosed at this time.” Although no further information is offered, this would usually indicate vulnerabilities of a critical nature that may already be subject to exploitation in the wild. It’s not unusual to withhold details on such things until a majority of users have had the opportunity to install the protective patch.

  • The good news is that the latter should be bundled with the former, and most device vendors will just issue the one complete update. Google said that the split is so that vendors have the flexibility to fix those vulnerabilities that are “similar across all Android devices more quickly” but confirmed that security patch level 2022-05-05 would include all the earlier fixes. Drew Barrymore’s First Grove Collaborative Campaign Takes An Optimistic Tone To Address Plastic’s Dire Problem Additional critical vulnerabilities patched for Google Pixel users Users of a Google Pixel phone should be especially time-critical in applying the update as this will include another 11 vulnerabilities unique to the device. The full details can be found here but the takeaway is that there are two critical vulnerabilities to be fixed. One is a remote code execution issue with the bootloader, the other an information disclosure issue with the Titan-M security chip.

