Kryptowire research: apps and firmware tweaks that Asus, LG, Essential, and ZTE add to Android phones sold in US come with serious vulnerabilities
SECURITY MELTDOWNS ON your smartphone are often self-inflicted: You clicked the wrong link, or installed the wrong app.
Context & Ripple Effects
Kryptowire's finding lands on a well-documented fault line: it was Google researchers examining the Galaxy S6 Edge who first showed an OEM's own additions can introduce a double-digit count of vulnerabilities into otherwise-patched Android. The new work extends that pattern from Samsung's software to the apps and firmware tweaks Asus, LG, Essential, and ZTE ship on US-sold phones.
It also compounds the patching problem rather than standing apart from it. A [[a:928468|study of roughly 1.2K 2017-model phones found OEMs frequently skip security patches they claim to install]], with ZTE among the worst offenders — so vulnerable vendor-added code is sitting on devices that already miss their update windows.
First-order effects
- Buyers of current Asus, LG, Essential, and ZTE handsets in the US are carrying exploitable vendor-added code today, with no action available until each manufacturer ships fixes for its own customizations.
- ZTE faces the sharpest exposure: its name appears both in this vulnerability research and in the earlier finding that it omitted multiple claimed patches, putting its US security posture under combined scrutiny.
Second-order effects
- Every Android OEM shipping heavy custom software now has to defend those additions as audited surface area, not differentiating features — a cost that pushes smaller vendors toward thinner skins closer to stock Android.
- Component- and platform-level players such as Qualcomm become the fallback fix channel when OEM updates lag, as seen when [[a:941021|Qualcomm patched a critical chipset flaw affecting dozens of its chips used in Android devices]]; buyers may increasingly weigh the silicon vendor's patch record alongside the phone brand's.
Third-order effects
- If the pattern holds — vendor-added code creating vulnerabilities on top of missed patches, and preinstalled malware later documented on low-cost Android phones and TVs — Android procurement will shift toward devices whose software provenance can be verified, squeezing out brands that cannot certify their own builds.
- The research lineage stretching back to a 20K-device study finding 87% of Android devices unpatched points toward regulation or carrier certification of OEM software practices as the durable fix, since market pressure alone has not closed the gap across nearly a decade of findings.
The trend: Android's security burden keeps migrating upstream — from user behavior to OEM-added software and patch discipline — making vendor customization practices, not just chipsets and app stores, the industry's recurring attack surface.