Google's Project Zero explains how the practice of altering the Android kernel by phone vendors like Samsung lessens security by adding attack surface
Google Project Zero scolds Samsung and other vendors for adding features that undermine Android security.
Context & Ripple Effects
This is a recurring finding, not a one-off: back in 2015, Google researchers tore down the Galaxy S6 Edge and found 11 vulnerabilities introduced by Samsung's own code — evidence that OEM feature additions were a security liability years before this write-up. Project Zero's argument here is the mechanism behind that pattern: every vendor modification to the Android kernel widens the attack surface Google has to defend.
The stakes are visible in what followed. The Android Partner Vulnerability Initiative, launched months after this piece, exists precisely to police OEM devices and surface their flaws to users. And in 2023, Project Zero found 18 zero-day vulnerabilities, four of them top-severity, in Exynos-powered Samsung phones — the kind of exposure that vendor-added code invites.
First-order effects
- Samsung and other Android vendors face direct pressure to strip or harden custom kernel code, since Project Zero's research shows their differentiating features are also their biggest security debt.
Second-order effects
- Google gains leverage over its partners: with the Partner Vulnerability Initiative already in place, kernel-level findings like these push OEMs toward closer adherence to Google's baseline security configuration rather than bespoke modifications.
Third-order effects
- If the pattern holds — risky OEM code in 2015, Exynos zero-days in 2023, an exploited kernel bug patched by Google in 2024 (46 vulnerabilities including a kernel zero-day under targeted exploitation) — Android security consolidates around upstream kernel discipline, narrowing how much vendors can safely customize the core OS.
The trend: Android is drifting from permissive OEM customization toward Google-enforced kernel hygiene, as each round of vendor-introduced vulnerabilities strengthens the case for upstream control.