Google fixed several security vulnerabilities in Android on October Patch Tuesday. According to the developers, the vulnerability is the most serious in a system component. This enables attackers from the Internet to inject malicious code without requesting or requiring any additional privileges.
Advertisement
In Google’s security bulletin for Android Patch Tuesday The developers have listed three vulnerabilities in the framework for patch level 2024-10-01. All of these were classified as high risk and affected Android 12, 12L, 13 and 14 – and among them the two new Android 15s, the source code of which has been available for about a month. There are four vulnerabilities found in Android’s system components; Three variants affect versions 12, 12L, 13, and 14, with one also affecting Android 15. The fourth vulnerability can only be found in Android 14.
more security improvements
There are also security vulnerabilities in Android’s ART runtime environment and WiFi components, which, however, are being closed with a Google Play system update. Security patch level 2024-10-05 fixes additional vulnerabilities in software from processor makers including Imagination Technologies, MediaTek, and Qualcomm.
According to Google, smartphone makers received the source code patch four weeks ago. So they already have time to develop updated firmware for their devices. Android smartphones that are still supported should expect a firmware update soon. Firmware updates for Google’s Pixel smartphones are still pending at the time of reporting. The situation as of September 2024 still persists there. The same picture can currently be seen with Samsung’s S24 flagship generation.
As of September Patch Tuesday, Google closed eleven security holes at the standard patch level 2024-09-01. One of these has already been actively attacked.

Besides Google, other manufacturers regularly publish security patches – but usually only for certain product lines. Devices from other manufacturers get the update much later or, in the worst case, not at all.
(DMK)
