Project Zero (Google's security research team) found a remotely exploitable vulnerability impacting Google Messages and reported internally back in June 2025 but the team at Android still have not fixed for the stock OS. People can have their device remotely exploited and taken over without any interaction from the victim with a known vulnerability.
https://project-zero.issues.chromium.org/issues/428075495
Another win for us, but truthfully, users shouldn't have to install a third party operating system like #GrapheneOS to have protection against such a thing. Any responsible team would have patched by now. iOS would have.
The same applies to getting security patches when they are created. An embargo of up to three months for vulnerability information and patches is unacceptable. We have patches scheduled for March 2026 coming in our security preview releases while most OEMs are just following the monthly Android Security Bulletins.
Google's ongoing layoffs and recent misguided changes to the security update model have significantly reduced stock Android security.
Login to reply
Replies (6)
There's no phone number I know of that reaches my phone, so this wouldn't work on me.
Is this reply pointless for people who have phone numbers? You might think so, but no. Open your mind. Get out of your box. Follow my example.
Most likely they get paid every day by the feds to not patch it.
They released a statement explicitly stating that this vulnerability is a feature not a bug.
just a small startup
Closed Source Proprietary Software is a thing of beauty
You can not hate #Google enough! š¤¬