Google's AndroidX Security State Enables Component-Level Patch Verification
Google introduced the AndroidX Security State and Security State Provider libraries, letting apps verify Android security at the component level instead of relying on a single device-wide patch date. The library distinguishes three patch levels — Device SPL, Published SPL, and Available SPL — for the kernel, system, and Google Play modules.
- Three patch levels: Device SPL, Published SPL, and Available SPL
- Verification covers kernel, system, and Google Play modules
- areCvesPatched() and isDeviceFullyUpdated() check specific CVEs
- Security State Provider standardizes update notifications for OEMs
Read next
Software