upvote
Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?
reply
Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.
reply
Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.
reply
>Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them.

Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.

reply
Pixels running GrapheneOS sure, but stock Pixels lag months behind patches that exist but not yet shipped. Check any bulletin and it links to git commits to months ago.
reply
>Check any bulletin and it links to git commits to months ago.

Is there any evidence that the git commits weren't in the ROMs from months ago? The monthly ASB corresponds to when the bugs are publicly disclosed, not when they made it into ROMs.

reply
Pixels only ship a tiny subset of the security preview patches early. Samsung ships a subset for their flagship devices too and it's likely larger than Pixels. Samsung lists these patches in their bulletins and you can retroactively figure out which were future Android Security Bulletin patches. Go through the vulnerabilities for September 2026 or October 2026 and search for them in Samsung's bulletin.

The only way to get the full set of security preview patches is through GrapheneOS. It's strange Google doesn't ship more for the Pixel OS but that's the way it is right now. It takes them around 4 weeks to make a release and even longer when including the time for adding changes to it so there's a long delay built into the process. They should fix it but are clearly not prioritizing it without media pressure that's not happening. They do a lot better than other OEMs but that's much different from doing a good job.

reply
Android Security Bulletins don't list the vast majority of firmware, driver, HAL and especially Linux kernel vulnerabilities. Those list a large subset of the High and Critical severity Android Open Source Project (AOSP) vulnerabilities backported to older releases along with a tiny portion of non-AOSP vulnerabilities. AOSP vulnerabilities below High and Critical severity aren't backported so those aren't listed. Non-AOSP vulnerabilities for Pixels are covered in the Pixel Update Bulletins with many of those being vulnerabilities in components used by other devices. Each OEM is supposed to make their own equivalent to the Pixel Update Bulletins, but they aren't required to provide those updates to claim the latest patch level.
reply
In a practical sense, what are the consequences of that? If you're careful about not installing random shit on your phone?
reply
It has remotely exploitable vulnerabilities in the firmware, Linux kernel, kernel drivers, userspace drivers and HALs. Those don't require installing anything on your device to exploit. There are publicly available proof of concept exploits for a bunch of these vulnerabilities.
reply
Well, it might be worth it reversing firmwares now with UART pins connected. A lot has changed in (agentic) reverse engineering.

BRB gonna try this out on my old Fairphone

reply