GrapheneOS accessed Android security patches but not allowed to publish sources

grapheneos.social

315 points by uneven9434 2 days ago


transpute - 2 days ago

Related discussion earlier this week, https://news.ycombinator.com/item?id=45158523

LinAGKar - 2 days ago

So basically to summarize, Google embargoes security patches for four months so OEMs can push out updates more slowly. And if those patches were immediately added to an open source project like GrapheneOS, attackers would gain info on the vulnerabilities before OEMs provide updates (the GrapheneOS project can see the patches, but they can't ship them). But a lot of patches end up being leaked anyway, so the delay ends up being pointless.