Study of 20K Android devices finds 87% vulnerable to security bugs due to manufacturers' failure to deliver patches
report Charlesarthur / The Overspill : Start up: inside a content factory, US reacts to Safe Harbour sinking, why Surface?, Android lemons and more Liam Spradlin / Android Police : Device Art Generator Updated With Nexus 5X And 6P Shells David Steele / AndroidHeadlines.com : AH Primetime: Cambridge University Analyze Android Security Risk Brad Reed / BGR : Google-funded study reveals Android security is a total disaster David Curry / Digital Trends : Google-commissioned security report paints a bleak picture of Android
Context & Ripple Effects
The Cambridge study quantifies a problem the coverage had already flagged two months earlier, when reporting showed how OEMs and carriers make Android's update strategy ineffective at scale. What changes here is measurement at device level: 87% of 20,000 phones tested were running known-vulnerable builds, and the study was commissioned by Google itself — turning an industry critique into an admission from inside the ecosystem.
That admission matters because the attack surface it exposes was already live: within months, critical bugs in older Android devices were being targeted by malvertising and drive-by exploits, so the patching gap translated directly into exploit traffic rather than remaining theoretical risk.
First-order effects
- Google now owns public evidence — funded by its own commission — that its open-device model leaves the vast majority of users unpatched, forcing it to respond on the record rather than defer to OEMs.
- Manufacturers named in the study face direct reputational pressure, since the finding ties vulnerability specifically to their failure to deliver patches, not to flaws in Google's platform code alone.
Second-order effects
- Google's subsequent annual security reports institutionalized the criticism against its partners — by end-2016 half of in-use devices had gone a year without any platform security update, keeping OEM patch performance under standing scrutiny.
- Follow-on research hardened the accountability loop: when testers examined newer 2017 handsets they found OEMs often don't install the very patches they claim, meaning vendor assurances became independently checkable rather than taken on trust.
Third-order effects
- If the pattern holds, Google ends up policing its own supply chain — culminating in the Android Partner Vulnerability Initiative to audit OEM security and surface device-specific flaws to users — effectively centralizing responsibility that fragmentation had pushed onto dozens of vendors.
The trend: Android's security model has been migrating from voluntary OEM patch delivery toward Google-enforced partner accountability, driven first by independent measurement and then by Google's own commissioned research.