Deploying Android Security Updates: an Extensive Study Involving Manufacturers, Carriers, and End Users
Kailani R. Jones, Ting-Fang Yen, Sathya Chandran Sundaramurthy, Alexandru G. Bardas
Abstract
Android's fragmented ecosystem makes the delivery of security updates and OS upgrades cumbersome and complex. While Google initiated various projects such as Android One, Project Treble, and Project Mainline to address this problem, and other involved entities (e.g., chipset vendors, manufacturers, carriers) continuously strive to improve their processes, it is still unclear how effective these efforts are on the delivery of updates to supported end-user devices. In this paper, we perform an extensive quantitative study (Aug. 2015 to Dec. 2019) to measure the Android security updates and OS upgrades rollout process. Our study leverages multiple data sources: the Android Open Source Project (AOSP), device manufacturers, and the top four U.S. carriers (AT&T, Verizon, T-Mobile, and Sprint). Furthermore, we analyze an end-user dataset captured in 2019 (152M anonymized HTTP requests associated with 9.1M unique user identifiers) from a U.S.-based social network. Our findings include unique measurements that, due to the fragmented and inconsistent ecosystem, were previously challenging to perform. For example, manufacturers and carriers introduce a median latency of 24 days before rolling out security updates, with an additional median delay of 11 days before end devices update. We show that these values alter per carrier-manufacturer relationship, yet do not alter greatly based on a model's age. Our results also delve into the effectiveness of current Android projects. For instance, security updates for Treble devices are available on average 7 days faster than for non-Treble devices. While this constitutes an improvement, the security update delay for Treble devices still averages 19 days.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e0e04bf1-0fb4-4f11-a9a9-d8d96bae8610Cited by top-tier papers5
- Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android KernelsLukas Maar, Florian Draschbacher, Lukas Lamster, Stefan MangardUSENIX Security 2024 · 5 citations
- The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel VulnerabilitiesLukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García et al.USENIX Security 2025
- 50 Shades of Support: A Device-Centric Analysis of Android Security UpdatesAbbas Acar, Güliz Seray Tuncay, Esteban Luques, Harun Oz et al.NDSS 2024
- Security in the Air: Understanding IoT Vendor Practices and the Economics of Over-the-Air UpdatesHuancheng Hu, Christian DoerrUSENIX Security 2026
- Vulnerability, Where Art Thou? An Investigation of Vulnerability Management in Android Smartphone ChipsetsDaniel Klischies, Philipp Mackensen, Veelasha MoonsamyNDSS 2025
Builds on4
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- An Analysis of Pre-installed Android SoftwareJulien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador et al.S&P 2020 · 105 citations
Related papers
- An Investigation of the Android Kernel Patch EcosystemZheng Zhang, Hang Zhang, Zhiyun Qian, Billy LauUSENIX Security 2021 · 45 citations
- Trust, But Verify: A Longitudinal Analysis Of Android OEM Compliance and CustomizationAndrea Possemato, Simone Aonzo, Davide Balzarotti, Yanick FratantonioS&P 2021 · 21 citations
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
- Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMsChao Wang, Yanjie Zhao, Jiapeng Deng, Haoyu WangS&P 2025
- Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable IdentifiersMark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng et al.NDSS 2023
