Google’s Might 2022 updates for Android are out.

As typical, the core of Android obtained two totally different patch variations.

The primary is dubbed 2022-05-01, and accommodates fixes for 13 CVE-numbered vulnerabilities.

Thankfully, none of those are at present being exploited, that means that there aren’t any zero-day holes recognized this month; none of them straight result in distant code execution (RCE); and none of them are flagged as Important.

Nonetheless, at the least one among these vulnerabilties might enable a completely innocent-looking app (one which wants no particular privileges in any respect once you set up it) to realize what quantities to root stage entry.

If you happen to’re questioning why we aren’t supplying you with particular CVE numbers for probably the most critical vulnerabilities, that’s as a result of Google itself doesn’t element which vulnerabilities current what dangers, however as an alternative merely states the potential side-effects of “probably the most extreme vulnerability” in every group of bugs.

The second tranche of updates is dubbed 2022-05-05, an official identifier that covers all of the patches supplied by 2022-05-01, plus 23 extra CVE-numbered bugs in quite a few elements of the working system.

Parts affected by these bugs embody the Android kernel itself, together with numerous closed-source software program modules which are supplied to Google by {hardware} makers MediaTek and Qualcomm.

Non-unified patches

Ideally, Google wouldn’t break up the month-to-month updates aside on this style, however would offer a single, unified set of patches and anticipate all distributors of Android units to get up-to-date as quickly as potential.

Nonetheless, as the corporate admits in its bulletins, there are “two safety patch ranges in order that Android companions have the pliability to repair a subset of vulnerabilities which are related throughout all Android units extra shortly.”

We are able to perceive Google’s strategy, which presumably displays the belief that it’s higher if everyone fixes at the least one thing and a few distributors repair the whole lot…

…than if some distributors repair the whole lot however others repair nothing in any respect.

Nonetheless, Google publicly notes that “Android companions are inspired to repair all points on this bulletin and use the newest safety patch stage.”

Within the trendy vernacular, our opinion on this problem is straightforward and clear: +1.