Microsoft issued patch for Wi-Fi flaw; Android fix expected in “coming weeks”, first to Pixels; researchers: 41% of Android devices are vulnerable
Technology companies are starting to respond to a new Wi-Fi exploit affecting all modern Wi-Fi networks using WPA or WPA 2 encryption.
Context & Ripple Effects
Microsoft is first out of the gate on KRACK, shipping a Windows patch while Google's Android fix waits 'coming weeks' — with Pixels first in line and researchers estimating 41% of Android devices exposed in the meantime. The response gap echoes April's Project Zero finding of a Broadcom Wi-Fi chipset flaw, where iOS was patched before Android even had a date.
The deeper pattern is delivery, not discovery: back in September 2016, Google issued fixes for a critical privilege-escalation bug only to find a large percentage of phones ineligible to receive them — the same fragmentation problem that makes a 41% vulnerable share plausible now.
First-order effects
- Windows users get immediate protection via Microsoft's patch, while the 41% of Android devices running affected versions stay exposed until Google's fix lands on Pixels first.
- Google's update pipeline becomes the bottleneck: every non-Pixel Android owner's protection depends on how fast OEMs and carriers relay the patch.
Second-order effects
- Device makers and carriers face pressure to shorten their patch relay chains, because each week of delay leaves their customers measurably exposed against a public exploit.
- Security research attention shifts from protocol design to vendor implementation quality, rewarding platforms that can ship fixes fastest — an advantage Microsoft just demonstrated.
Third-order effects
- If protocol-level flaws keep landing faster than fragmented fleets can absorb patches, update delivery speed hardens into a competitive differentiator between tightly controlled hardware like Pixels and carrier-gated Android — and pushes vendors toward OS-level mitigations that don't depend on WPA2 alone.
- Regulators and enterprises gain a concrete metric for supply-chain risk: time-to-patch across a vendor's installed base, not just whether a fix exists.
The trend: As protocol-level vulnerabilities hit billions of devices at once, the decisive security variable is shifting from who finds the flaw to which platform can actually deliver the fix across its fleet.