Google's Project Zero team finds address space layout randomization offers less protection against Stagefright than Google PR claims
There's been a lot of attention recently around … Tweets: Christopher Soghoian / @csoghoian : Android team: Stagefright isn't that bad. Android has additional security measures. Google security team: Nope. http://arstechnica.com/... Peter Bright / @drpizza : So you'd think Google would have known better, and indeed, its own researchers have pointed this out. http://arstechnica.com/... Thanks: @accretivegrowth
Context & Ripple Effects
This lands a month after Stagefright forced Android to rethink its security model, and two weeks after Google's first fix had to be reissued because it caused system crashes. The new wrinkle is internal: Google's own Project Zero researchers are publicly contradicting the Android team's line that mitigations like ASLR blunt the bug.
The dispute matters because Google PR was leaning on ASLR to downplay severity while its security team says the mitigation doesn't hold against Stagefright — an unusually public split between a company's marketing arm and its elite vulnerability researchers.
First-order effects
- The Android team's public reassurance campaign is undercut by its own researchers, forcing Google to defend severity claims made by one part of the company against findings from another.
Second-order effects
- Pressure to actually neutralize Stagefright rather than talk it down accelerates the patching grind — the effort that ends up spanning 115 Stagefright-related flaws patched over the following year.
Third-order effects
- If mitigation-based reassurance keeps failing audit by in-house researchers, the durable answer shifts toward reducing attack surface itself — the direction Project Zero later takes in criticizing how vendors like Samsung modify the Android kernel and add exposure.
The trend: Android's security posture is moving from marketing mitigations to verifiable hardening, driven by Project Zero holding the platform side of Google publicly accountable.