Get the latest tech news

Google Shifts Android Security Updates To Risk-Based Triage System


Google has restructured Android's decade-old monthly security update process into a "Risk-Based Update System" that separates high-priority patches from routine fixes. Monthly bulletins now contain only vulnerabilities under active exploitation or in known exploit chains -- explaining July 2025's un...

Google has restructured Android's decade-old monthly security update process into a "Risk-Based Update System" that separates high-priority patches from routine fixes. Monthly bulletins now contain only vulnerabilities under active exploitation or in known exploit chains -- explaining July 2025's unprecedented zero-CVE bulletin -- while most patches accumulate for quarterly releases.The September 2025 bulletin contained 119 vulnerabilities compared to zero in July and six in August. The company no longer releases monthly security update source code, limiting custom ROM development to quarterly cycles.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Google

Google

Photo of Android

Android

Photo of risk

risk

Related news:

News photo

Google’s huge new Essex datacentre to emit 570,000 tonnes of CO2 a year

News photo

New VoidProxy phishing service targets Microsoft 365, Google accounts

News photo

Rolling Stone, Billboard owner Penske sues Google over AI overviews