Google Rethinks Android Security Beyond Single Patch Date
Google has released two new libraries, AndroidX Security State 1.1.0 and Security State Provider 1.0.0, to help developers and administrators determine a device's true security posture.
The tools will allow apps and administrators to inspect device security by distinguishing between the core Android system, modular components delivered through systems such as Google Play updates, and the Linux kernel.
Instead of relying on a single Security Patch Level (SPL), the libraries track three distinct indicators: Device SPL (DSPL), Published SPL (PSPL), and Available SPL (ASPL).
The new libraries will provide more precise security information to apps, allowing them to make informed decisions about device security. This could eventually lead to fewer situations where an app treats an entire device as outdated simply because its headline patch date is old.