Return
VirtualPatch: Distributing Android security patches through Android virtualization
DOI:10.1016/j.cose.2025.104615.png)
Abstract
En 中文
The Android Operating System (OS) is a complex system that might contain vulnerabilities and allow malicious apps to damage the legitimate ones on the same device or steal sensitive user data. Vulnerabilities in the Android OS are fixed through security patches that can only be distributed through an update of the whole OS. Google is responsible for the development of security patches for the official Android platform i.e., the Android Open Source Project (AOSP). However, several other mobile vendors (e.g., Samsung, Xiaomi) sell smartphones running a customized version of AOSP and are responsible for integrating the AOSP security patches into their custom OS. This integration should occur before Google makes a vulnerability and the associated security patch public. Unfortunately, this is not always the case: we have found that the median time that Samsung requires to integrate a security patch is 35 days. This is astonishing and confirms the urgent need for a solution.
Keywords:
Android security
Application-level virtualization
Security patch deployment
Android hooking techniques
Android user protection
Journal
C
IF:
5.4
Papers:
4.6K
Citations:
1.4W
Organization
No organization information available

