The month of July is already a few days old and not quite on time for the start of the first working week of the month (today on Wednesday) Google released the current Android security update.
As usual, the rollout to the Pixel smartphones begins immediately after the announcement, so the first security gaps are patched, problems are fixed and possible new features are brought to the devices in these minutes. In addition, users of Pixel smartphones can look forward to a separate update again.
Many bugs and security vulnerabilities were reported in Android for the month of July, with the same components being the focus of the problems or bugs found and allowing the execution of arbitrary code as every month – an all-time classic. But even in the seventh month of 2022 there are a number of other plugged gaps in the system component and the Qualcomm components. In total, the developers discovered and patched 3 critical and 30 medium vulnerabilities this month.
In most cases, Google only publishes the details of the security gaps and bugs after the update has been rolled out, so that they could not be exploited in the past, which, as usual, was proud to be reported this month.
The most severe of these issues is a critical vulnerability in the Media Framework component that could allow a remote attacker to use a specially crafted file to run arbitrary code in the context of a privileged process.
The severity rating is based on the impact that exploiting the vulnerability would potentially have on an affected device, assuming the platform and service mitigations are disabled for development purposes or if bypassed successfully.
We have had no reports of active customer exploitation or abuse of these newly reported issues. Refer to the Android and Google Play Protect mitigations section for details on the Android security platform protections and Google Play Protect, which improve the security of the Android platform.
Update for the Pixel smartphones
The Pixel smartphones have fixed some security gaps and fixed problems, but also have something to offer in a functional way – at least under the hood. Pixel 6 smartphone users can look forward to the fact that VoLTE has now been activated in some networks.
Telephony
Enable additional VoLTE calling features on certain networks.
If you don’t want to wait for the update via OTA, you can download both the factory and OTA images for the Pixel smartphones directly from Google. Details on all gaps can be found directly under the following links, in which the individual problems with the components are listed and explained in detail.
Security Bulletin: Android Security Bulletin July 2022 | Pixel Security Bulletin July 2022
Images for download: Factory Images | OTA images