Mishaal's Android News Feed
Google has published the Android Security Bulletin (ASB) for December 2023, detailing the vulnerabilities addressed in the 2023-12-0X security patch level (SPL). Patches are available for Android versions 11-14. There are 3 vulnerabilities in AOSP components…
The technical write-up for CVE-2023-45779 has been published by Tom Hebb of Meta's Red Team X, revealing that several Android OEMs such as ASUS, Fairphone, Lenovo, Microsoft, Nokia, Nothing, and Vivo, were signing some of their APEX modules with the test keys publicly available in AOSP.
This would have allowed a user or attacker (with shell privileges) to forge an APEX update to "gain near-total control over [the device]."
This issue was fixed by most affected OEMs with the December 2023 security patch, though, and it's quite hard to exploit by actual attackers - still, the issue reveals deficiencies in the Compatibility Test Suite (CTS) and AOSP documentation that are being resolved in response.
Google says they've added a test to their Build Test Suite (BTS) to warn of vulnerable APEXes and that changes to CTS are coming (but the latter won't be public until Android 15's release).
This would have allowed a user or attacker (with shell privileges) to forge an APEX update to "gain near-total control over [the device]."
This issue was fixed by most affected OEMs with the December 2023 security patch, though, and it's quite hard to exploit by actual attackers - still, the issue reveals deficiencies in the Compatibility Test Suite (CTS) and AOSP documentation that are being resolved in response.
Google says they've added a test to their Build Test Suite (BTS) to warn of vulnerable APEXes and that changes to CTS are coming (but the latter won't be public until Android 15's release).
😱47👍18🤪6😁3🤔1
2024 may be the year of Bluetooth LE Audio as we see many new products release with support for it.
To prepare for this, Google's working on an audio sharing page in Android 15 that makes it easier to start or connect to Auracast streams!
To prepare for this, Google's working on an audio sharing page in Android 15 that makes it easier to start or connect to Auracast streams!
Android Authority
Android 15 prepares to let you share media audio to nearby devices
Headsets with support for broadcasting audio are coming this year, so Google is preparing to add a dedicated audio sharing page in Android 15
👍46❤9👏5
Google is making it easier to transition your online accounts to passkeys. Google Password Manager on Pixel devices (Pixel 5a and later, including Pixel Tablet) is rolling out a passkey upgrade experience that helps you discover which of your accounts support passkeys and then helps you upgrade with "just a few taps."
This is available now on the aforementioned Pixel devices but will be coming to "other platforms" in the future. Currently this works with Adobe, Best Buy, DocuSign, eBay, Kayak, Money Forward, Nintendo, PayPal, Uber, and Yahoo! Japan but will be coming soon to TikTok as well.
This is available now on the aforementioned Pixel devices but will be coming to "other platforms" in the future. Currently this works with Adobe, Best Buy, DocuSign, eBay, Kayak, Money Forward, Nintendo, PayPal, Uber, and Yahoo! Japan but will be coming soon to TikTok as well.
👍68🔥15
Samsung is rolling out an update to its Quick Share app on Galaxy devices that adds support for Google's Nearby protocol, which will allow for other Android devices with Nearby Share (soon to itself be renamed Quick Share) to appear in Samsung's Quick Share service.
This updated version of Quick Share is already preloaded on the Galaxy S24 series, but it's now rolling out to older Galaxy devices. However, users who have received the update report that sharing with Nearby Share-enabled devices doesn't actually work yet despite what the changelog says. Also, Google's Nearby Share still appears as an option in the share sheet, but this should be disabled like on the Galaxy S24 series once Samsung's Quick Share update widely rolls out and the new functionality goes live.
The update also increases the upload limit per file when creating QR codes and using share to contacts (from 3GB --> 5GB).
Image credits: @gepetto888
This updated version of Quick Share is already preloaded on the Galaxy S24 series, but it's now rolling out to older Galaxy devices. However, users who have received the update report that sharing with Nearby Share-enabled devices doesn't actually work yet despite what the changelog says. Also, Google's Nearby Share still appears as an option in the share sheet, but this should be disabled like on the Galaxy S24 series once Samsung's Quick Share update widely rolls out and the new functionality goes live.
The update also increases the upload limit per file when creating QR codes and using share to contacts (from 3GB --> 5GB).
Image credits: @gepetto888
👍57❤6🆒6👏3🎉3
This is the best evidence yet that Amazon is shifting Fire TV away from AOSP: An Amazon job posting for a SDE asks the candidate to "implement and deliver features on the Fire TV client codebase as it transitions from FOS/Android to native/Rust and React Native."
Great find by Elias Saba over on AFTVnews. Last year, Janko Roettgers reported on his newsletter called Lowpass that Amazon is ditching AOSP for an in-house operating system code-named Vega.
Great find by Elias Saba over on AFTVnews. Last year, Janko Roettgers reported on his newsletter called Lowpass that Amazon is ditching AOSP for an in-house operating system code-named Vega.
👍34😭12👀8😱6🤣5
Mishaal's Android News Feed
This is the best evidence yet that Amazon is shifting Fire TV away from AOSP: An Amazon job posting for a SDE asks the candidate to "implement and deliver features on the Fire TV client codebase as it transitions from FOS/Android to native/Rust and React Native."…
I wouldn't be surprised if we get at least one more major version of Fire OS based on AOSP, potentially Android 14.
An Amazon engineer has been submitting patches to AOSP fixing issues with SD cards and introducing a new stylus-related setting, the latter of which was just submitted, so it's possible they're cooking up Fire OS 9 based on Android 14 as potentially their last AOSP-based release. Maybe for new devices that were planned before the transition? Or this could just be abandoned, who knows.
An Amazon engineer has been submitting patches to AOSP fixing issues with SD cards and introducing a new stylus-related setting, the latter of which was just submitted, so it's possible they're cooking up Fire OS 9 based on Android 14 as potentially their last AOSP-based release. Maybe for new devices that were planned before the transition? Or this could just be abandoned, who knows.
🤔25👍14
Developers can now show users a full-screen prompt to get them to update their app, in case they're running an outdated or broken version.
This feature is available if you're enrolled in Play App Signing and distributing your app as an Android App Bundle. Prompts can be narrowed down to users on a selected app version, by country/region, or by Android version. If the full-screen prompt is dismissed, it will be shown again on the next cold start of the app.
This feature is available through the Google Play Console by going to the Releases overview or App Bundle Explorer page and clicking Recovery tools > Prompt users to update.
More details on Google's blog post.
This feature is available if you're enrolled in Play App Signing and distributing your app as an Android App Bundle. Prompts can be narrowed down to users on a selected app version, by country/region, or by Android version. If the full-screen prompt is dismissed, it will be shown again on the next cold start of the app.
This feature is available through the Google Play Console by going to the Releases overview or App Bundle Explorer page and clicking Recovery tools > Prompt users to update.
More details on Google's blog post.
👍82👎25❤13👌4🤔2👏1
Google may have started rolling out Quick Share to some Android users. One user reports seeing the new Quick Share (formerly called Nearby Share) on their Pixel phone.
Let me know if you see Quick Share on your Android device! (Thanks to @Felixlix45 for the tip!)
Note: Google's Quick Share is not the same as Samsung's Quick Share, though they're now interoperable. Google's Quick Share is part of Google Play Services, while Samsung's is through its Quick Share app which is being updated to become interoperable with Nearby Share (now Quick Share) on other Android devices.
Edit: Four more people (also with Pixel phones) have responded to me saying they've received Quick Share, so it looks like it's indeed rolling out.
Let me know if you see Quick Share on your Android device! (Thanks to @Felixlix45 for the tip!)
Note: Google's Quick Share is not the same as Samsung's Quick Share, though they're now interoperable. Google's Quick Share is part of Google Play Services, while Samsung's is through its Quick Share app which is being updated to become interoperable with Nearby Share (now Quick Share) on other Android devices.
Edit: Four more people (also with Pixel phones) have responded to me saying they've received Quick Share, so it looks like it's indeed rolling out.
👍98👏5🥰3💯3❤1
Mishaal's Android News Feed
Circle to Search will roll out to the Pixel 8 and Pixel 8 Pro next week, but if you want to find out how to enable it right now, I shared the method with my subscribers over on Patreon. It can be enabled on the Pixel 8 series without root, but requires root…
Circle to Search is now rolling out to the Pixel 8 and Pixel 8 Pro!
You won't get a notice that it's there, so just check by performing the gesture. Lots of Pixel 8 users on Reddit are reporting that it's working for them now.
You won't get a notice that it's there, so just check by performing the gesture. Lots of Pixel 8 users on Reddit are reporting that it's working for them now.
Reddit
From the GooglePixel community on Reddit
Explore this post and more from the GooglePixel community
👍59🔥9🆒6👏2🤬2
The PC apps for Samsung's Quick Share and Google's Nearby Share are reportedly going to be "integrated" by Q3 of 2024, according to a Samsung Quick Share platform manager.
Also:
* Samsung says their rollout of the latest version of Quick Share to Galaxy devices will be completed by tomorrow. You'll need these 4 APKs:
Quick Share: v13.6.11.7
Quick Share Connection: v1.5.2.30
Quick Share Agent: v3.5.19.23 (T OS), v3.5.14.38 (Q/R/S OS)
Wi-Fi Direct: v3.4.14.35 (Q/R OS)
* Google's rollout of Quick Share on other Android devices is scheduled for between 2/2 - 2/16, though as I first reported last night, this rollout has already begun. Once this rollout is complete, the Nearby Share button will disappear on Samsung devices.
Also:
* Samsung says their rollout of the latest version of Quick Share to Galaxy devices will be completed by tomorrow. You'll need these 4 APKs:
Quick Share: v13.6.11.7
Quick Share Connection: v1.5.2.30
Quick Share Agent: v3.5.19.23 (T OS), v3.5.14.38 (Q/R/S OS)
Wi-Fi Direct: v3.4.14.35 (Q/R OS)
* Google's rollout of Quick Share on other Android devices is scheduled for between 2/2 - 2/16, though as I first reported last night, this rollout has already begun. Once this rollout is complete, the Nearby Share button will disappear on Samsung devices.
👍59❤14✍2🎉1
Many custom kernel users are now seeming to fail device attestation checks, and the cause appears to be that the Play Integrity API is checking for blacklisted strings in the kernel version name.
For example, kernels with "sultan" or "lineageos" in the uname are reportedly failing attestation.
And it looks like Play Integrity might soon add GPU driver fingerprinting as well.
Neither of these checks are surprising, but it's yet another thing that root users need to be aware of in this neverending cat-and-mouse game.
Discussion here.
For example, kernels with "sultan" or "lineageos" in the uname are reportedly failing attestation.
And it looks like Play Integrity might soon add GPU driver fingerprinting as well.
Neither of these checks are surprising, but it's yet another thing that root users need to be aware of in this neverending cat-and-mouse game.
Discussion here.
🤬147🤡31🗿14👍10😭8❤5👎5🤔3😁2🤮2😡2
Google's Quick Share rebrand also brings with it a new feature: the ability to select targets directly from the share sheet!
Full details in this article on Android Police.
Full details in this article on Android Police.
Android Police
Google's Quick Share update makes sharing files even easier than before
Google's Quick Share rollout wasn't the only big shakeup the company made to sharing files on Android today
👍61🔥24
Mishaal's Android News Feed
Google has halted the rollout of the January 2024 GPSU following reports of devices having file access issues. Over the past few days, several users on Reddit, particularly those with Pixel phones, have faced issues with file access. The internal storage…
If you have a Pixel phone and have been unable to access your files after updating to the January 2024 Google Play System Update, Google has shared a fix.
1) Download and set up ADB on your PC (there are many tutorials online for this).
2) Connect your phone to your PC and run the following ADB commands:
3) Reboot your phone.
Google says that this issue is more prevalent in devices with multiple user accounts and/or work profiles and that they working on a fix for the root cause of this issue. Google's temporary solution today involves uninstalling updates to the Media and Medic Codecs Mainline modules.
Last week, I learned from a source that Google halted the January 2024 GPSU because they discovered that the DCLA Mainline module was inadvertently rolling back to the factory installed version for some users, causing mismatched dependency issues with other DCLA-enabled modules. It looks like both Media and Medic Codecs are DCLA-enabled modules, and this mismatch caused them to misbehave and resulted in the storage access-related issues that some users have been facing.
For a more detailed step-by-step guide, see Google's post on the Pixel community forums.
1) Download and set up ADB on your PC (there are many tutorials online for this).
2) Connect your phone to your PC and run the following ADB commands:
adb uninstall com.google.android.media.swcodecadb uninstall com.google.android.media3) Reboot your phone.
Google says that this issue is more prevalent in devices with multiple user accounts and/or work profiles and that they working on a fix for the root cause of this issue. Google's temporary solution today involves uninstalling updates to the Media and Medic Codecs Mainline modules.
Last week, I learned from a source that Google halted the January 2024 GPSU because they discovered that the DCLA Mainline module was inadvertently rolling back to the factory installed version for some users, causing mismatched dependency issues with other DCLA-enabled modules. It looks like both Media and Medic Codecs are DCLA-enabled modules, and this mismatch caused them to misbehave and resulted in the storage access-related issues that some users have been facing.
For a more detailed step-by-step guide, see Google's post on the Pixel community forums.
👍71😁8🤡6🤔2
I've been using Android's Circle to Search on the Galaxy S24 for over two weeks now, but I JUST learned that you can move the search bar and zoom in!
How did we all miss this? Video available in this Android Police article.
How did we all miss this? Video available in this Android Police article.
Android Police
Here’s a little known way to use Circle to Search
Google's Circle to Search feature on the Galaxy S24 and Pixel 8 series will get out of your way when you need it to
👍45🔥12🤯6👎4❤1
The OnePlus 12 joins Google's Pixel lineup and Samsung's Galaxy S24 series in supporting Android 14's Ultra HDR format! This means HDR photos you capture from the OnePlus 12 can be shown properly on both SDR and HDR displays.
Full details on what this means are available over on Android Police.
Full details on what this means are available over on Android Police.
Android Police
The OnePlus 12's first update adds Ultra HDR support in Google Photos
Android 14's new Ultra HDR format seems to be catching on
👍62🎉8❤6👏5
Wish more Android apps would go edge-to-edge, ie. take up 100% of your screen? Google has heard you, because they're working on adding a config in Android 15 that forces apps to go edge-to-edge by default!
Full details in this Android Authority article.
Full details in this Android Authority article.
Android Authority
Android 15 might force more apps to take up 100% of your screen
Android apps can go edge-to-edge to take up the entire screen, but many choose not to support this. Android 15 could force them to.
❤82👍22🔥21🐳4