Google researchers examine Galaxy S6 Edge and show OEMs add risky code as they find 11 vulnerabilities introduced by Samsung
Lucian Constantin / Computerworld :
Context & Ripple Effects
Google's Project Zero teardown of the Galaxy S6 Edge lands three weeks after a study of 20K Android devices found 87% vulnerable largely because manufacturers fail to ship patches. The new finding sharpens that picture: beyond missing updates, Samsung's own modifications introduced 11 vulnerabilities into the device.
The report also prefigures a decade-long arc — Project Zero would later document how vendor kernel alterations systematically add attack surface, Google would launch an Android Partner Vulnerability Initiative to police OEM code, and Samsung itself would ship ~100M phones with exploitable design flaws years after this audit.
First-order effects
- Samsung must fix 11 flaws of its own making in the Galaxy S6 Edge, on top of the patch-delivery gap already documented across Android vendors.
Second-order effects
- Other OEMs face the same audit exposure: Kryptowire later found serious vulnerabilities in firmware tweaks by Asus, LG, Essential, and ZTE sold in the US, showing vendor-added code is a systemic problem, not a Samsung one.
Third-order effects
- If OEM customization keeps introducing vulnerabilities, Android security pressure shifts from Google's core OS toward policing partner code — the direction Google formalized with its Partner Vulnerability Initiative and Project Zero's ongoing Exynos and kernel research.
The trend: Android's security burden is migrating upstream from Google's OS to the code OEMs layer on top of it, with Google increasingly auditing and pressuring partners directly.