← Home

Google wants to make Android phones safer with risk-based security updates

Google wants to make Android phones safer by switching to 'risk-based' security updates

Google is implementing a radical approach to Android security: instead of maintaining a uniform monthly update cadence for all devices, the company is adopting a "Risk-Based Update System" (RBUS). Under this new model, Google will prioritize shipping only "high-risk" vulnerabilities in its monthly bulletins, while the majority of security fixes will be delivered in quarterly releases.

The change represents a deep reevaluation of how Google handles vulnerabilities in the Android ecosystem. For the past decade, the company published an Android Security Bulletin (ASB) every month, even when it wasn't ready to roll out a security update to its own Pixel devices. These bulletins detail the vulnerabilities fixed in each release, with issues ranging from moderate to critical. Given the sheer size and complexity of the Android operating system and its underlying components, it's not unusual to see a dozen or more vulnerabilities documented in a monthly bulletin — and sometimes, none.

Now, Google will reclassify vulnerabilities as either "high-risk" or "low-risk." High-risk fixes will be shipped monthly, while low-risk fixes will be bundled into quarterly updates. Google defines "high-risk" vulnerabilities as those crucial to address immediately, such as those under active exploitation or part of a known exploit chain. This designation is based on real-world threat level, not just the technical severity rating of the bug.

Google's justification is clear: device manufacturers (OEMs) often struggle to roll out monthly updates for all their devices, especially when managing heavily customized versions of Android across massive device portfolios. In some regions, they need carrier approval to release updates. As a result, many Android devices are left without the latest security patches and vulnerable to exploitation.

The RBUS aims to solve this problem by simplifying the monthly process and giving manufacturers flexibility. Instead of bundling all available security fixes into the next ASB, OEMs will have fewer patches to merge, test, and ship monthly. This reduces the difficulty of shipping monthly updates and may result in some manufacturers shipping them more frequently across more devices.

As a direct consequence, the March, June, September, and December bulletins will be substantially larger. For instance, the September 2025 ASB listed 119 vulnerabilities, compared to zero and six listed in the July and August 2025 bulletins, respectively. OEMs are encouraged to adopt at least a quarterly update schedule for their devices to maximize user protection.

There are, however, downsides for the independent developer community. Under the change, Google is no longer releasing source code for monthly security updates, only for quarterly ones. Custom ROMs can no longer ship monthly updates. This adds to a growing pile of other factors making it harder to mod Android phones in 2025.

For most users, this new security release approach won't change much. If you already receive monthly security updates, you'll continue to get them. If you don't, this change may help your device's manufacturer deliver them more consistently. At the very least, it should make it easier for all OEMs to push out quarterly updates, which are now far more impactful.

The big question is whether Google's new approach will truly keep Android users protected against evolving threats, or whether focusing only on high-risk vulnerabilities will leave dangerous gaps that cybercriminals could exploit between quarterly bulletins.

Sources: Android Authority, Android Authority, The Hacker News

✓ Independent sources cross-checked and verified before publishing