UPDATED 01:01 EDT / OCTOBER 14 2015

NEWS

The elephant in the room: Study confirms Android devices vulnerable due to lack of patches

Researchers at the U.K.’s University of Cambridge have confirmed in a study a fact that has always been the elephant in the room when it comes to Android devices: they just aren’t getting the security patches they need to be kept secure.

The study found that 87 percent of Android devices are exposed to at least one critical vulnerability due to Android handset makers failing to deliver patches.

Data for the study came from over 20,000 Android devices with the Device Analyzer app installed, and was tested against 11 known Android bugs that have been in the public domain in the past five years.

“The difficulty is that the market for Android security today is like the market for lemons,” the researchers explained. “There is information asymmetry between the manufacturer, who knows whether the device is currently secure and will receive security updates, and the customer, who does not.”

Not all Android phones are equal however, with the study finding that Google Nexus devices are the most secure Android devices as they run stock Android installs that don’t rely on manufacturers or telcos to issue patches.

Of the rest, LG phones received the highest scores for security, although that figure may be slanted as LG also has been a primary manufacturer of Nexus phones.

With poorer results were phones manufactured by Motorola, Samsung, Sony and HTC, while smaller Android manufacturers (particularly those from China) worse again, with some phones never being provided updates even once.

“The security of Android depends on the timely delivery of updates to fix critical vulnerabilities,” the researchers added. “Unfortunately few devices receive prompt updates, with an overall average of 1.26 updates per year, leaving devices unpatched for long periods. We showed that the bottleneck for the delivery of updates in the Android ecosystem rests with the manufacturers, who fail to provide updates to fix critical vulnerabilities.”

Needs to be fixed

The issue with the deficient provision of Android security updates is fairly said to be the elephant in the room because it is an obvious truth that is either being ignored or going completely unaddressed by Google, phone makers and telcos equally.

There is no easy solution that can fix the market as it stands today given the diversity of Android installs, but it is a problem that needs to be fixed, and there is one way Google could do it: it could split out security patches in Android from operating system upgrades that outside of Google’s own Nexus line of phones require the manufacturer, then often also the telco, to push it out to customers.

It may not be the perfect solution that covers every single potential issue, but if Google was able to push out those patches independent of manufacturers and telcos it would definitely go so way in addressing what continues to become are increasing severe problem.

Image credit: taken-screenname/Flickr/CC by 2.0

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.