Get the latest tech news
Google may shift to risk-based Android security patch rollouts - what that means for you
Google is prioritizing critical real-world vulnerabilities while also improving the OEM patching process.
So, if a vulnerability is being actively exploited in the wild or is considered to be of extreme risk to user privacy and security, it will be patched more quickly than a low-risk denial-of-service memory issue, for example. As noted by the publication, however, there is a difference between an official "critical" rating as issued by authorities in CVSS scoring and what the tech giant could deem high risk. Android stops most vulnerability exploitation at the source with extensive platform hardening, like our use of the memory-safe language Rust and advanced anti-exploitation protections.
Or read this on ZDNet