hn.today

Google assigned 30 zero-click Android bugs, then closed them and shipped fixes

github.com11 points1 comments
Screenshot of Google assigned 30 zero-click Android bugs, then closed them and shipped fixes

A security researcher reports eight months of Android vulnerability research - over 85 submissions and 30+ distinct zero-click findings - detailing a pattern of how Google handled those reports. The researcher reverse-engineered Pixel and Samsung telephony components, submitted working proofs of concept, and then audited Google's shipped factory images to compare exact binaries and functions. Findings were classified into four verdicts (patched, still present, N/A, can't-determine) after byte-level comparison. The central claim: multiple reports were closed as duplicates, infeasible, or "not a vulnerability," yet eight of those closed reports were later changed in shipping code with no reward or credit, while many others remain unpatched despite closure. A promised $500 bounty for two older bugs was only half-paid, and the other half has been stalled in “manual exception” processing for over eight months.

The researcher documents specific technical fixes and failures: added permission guards for PixelModemService MintReceiver; bound-check additions in framework PduParser.parseParts; underflow and length checks in libpixelimsmedia components (RtpSession, RtcpChunk, RtpDecoderNode); and a privileged permission added to DeviceProvisioningService in ShannonRcs.apk. Administrative errors are highlighted too: Google admitted linking unrelated reports to the same internal canonical ID and retracted an earlier "not a security vulnerability" closure. The report alleges a recurring pattern of silent fixes, incorrect triage, and delayed or withheld payments, supported by direct binary diffs against shipped images.

Read on github.com1 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.