FCC and FTC ask smartphone makers and mobile carriers for information on phone patching process, express concern about long delays and unpatched older devices
FCC and FTC ask for information on process for issuing patches — Letters go to carriers AT&T, Verizon and to device makers
Context & Ripple Effects
This letter campaign extends the FCC's recent run of direct scrutiny of major carriers: just months after summoning T-Mobile, Comcast and AT&T to discuss their zero-rating programs, the agency is now pairing with the FTC to demand information from AT&T, Verizon and device makers on how security patches reach phones — and why older devices go unpatched.
The concern was well-founded by what came next in this coverage: Google's own fix for a critical privilege-escalation bug and a Stagefright-like flaw left a 'large percentage' of Android phones ineligible to receive it, and researchers who tested 1,200 phones from 2017 found OEMs frequently shipping devices without the patches they claimed to install.
First-order effects
- AT&T, Verizon and the receiving device makers must now document their patching pipelines for two federal agencies, turning internal update timelines into a matter of regulatory record.
- Carriers' role as gatekeepers of Android updates — the layer between Google's patches and users' handsets — comes under explicit examination for the first time in this coverage.
Second-order effects
- Regulatory attention on carrier conduct is converging from multiple directions: alongside these letters, the DOJ has subpoenaed the top four US carriers and GSMA over alleged collusion to impede eSIM-based switching, raising the cost of opaque carrier practices across the board.
- Device makers with weak update discipline face audit exposure — the later finding that ZTE and TCL each omitted four or more claimed patches shows exactly the gap the FCC and FTC are probing.
Third-order effects
- If the pattern holds, security updates move from a voluntary OEM marketing claim toward a disclosable, regulator-examined obligation, making patch cadence and device support lifespan a formal factor in how carriers and manufacturers are judged.
- The joint FCC-FTC approach signals that the carrier-OEM update chain is treated as a single accountability structure rather than a handset-maker problem alone.
The trend: US regulators are shifting from reacting to individual vulnerabilities toward systematically examining the carrier-and-OEM chain that determines whether Android phones actually get patched.