Study finds 87% of Android devices are insecure due to lack of security updates

by: Jimmy WestenbergOctober 14, 2015

From the Stagefright exploit to other recent security vulnerabilities found in the Android ecosystem, it’s no secret that device security has lately been on the minds of OEMs and consumers alike. A recent study, partially funded by Google and conducted by the University of Cambridge, shows that more Android devices might be more insecure than most of us think. According to a blog post from one of the researchers, Alastair R. Beresford, on average throughout the last four years, a whopping 87% of Android devices are vulnerable to attacks by malicious applications. Beresford says that this is due to device manufacturers not providing security updates on a regular basis. He comments that while some OEMs are much better than others, this is still a major problem.

The researchers collected this data by having approximately 20,000 users download and run their Device Analyzer application, which can be found in the Google Play Store. Thanks to the app collecting data from a wide range of devices, the researchers were able to rank OEMs on the proportion of devices free from critical vulnerabilities, the number of devices running the latest version of Android, and the average number of vulnerabilities the OEM has yet to fix on any device.

Cambridge study - Android vulnerabilities

So, which smartphone makers are the best at providing regular updates? According to the findings, Google’s Nexus devices scored the highest with a 5.2 out of 10, making them the safest handsets available. LG isn’t too far behind with a score of 4 out of 10, and Motorola ended up scoring a 3.1 out of 10. Samsung, Sony, HTC and ASUS have fallen behind with scores ranging from 2.7 down to 2.4.

Google, Samsung and a number of other manufacturers have been doing their part to bring monthly security updates to their range of current Android smartphones. The researchers hope that by quantifying the problem, they’ll be able to help people make a decision when choosing a device. This will, in turn, provide incentive for other OEMs to take regular security updates more seriously.

  • Prashant Gyawali

    How can a device be secure if your device doesn’t get listed for a new OS upgrade even if it fulfills the minimum requirement for running it? Nothing quite surprising here.

    • Jose Lugo

      Yea, horrible for Note 3 owners and some other devices!

      • 1213 1213

        If you own a note3 you probably don’t have warranty. You may as well just root it and install a custom ROM.

  • Brandon G

    so then samsung knox is just bullshit then?

    • gg

      Knox, knox…

      • JustJames

        Who’s there?

      • Happy

        Knock, knock Penny…knock, knock Penny…knock, knock Penny…

    • Daggett Beaver

      Knox by itself doesn’t do anything unless your phone is managed by a Knox-enabled server. If it’s a managed phone, then it isolates business usage from personal usage. Otherwise it just sits there doing nothing — except checking at boot to see if the phone is secure enough to run Knox if it’s needed. That’s why Knox will return an error if your phone is rooted or SELINUX is set to permissive.

      • Brandon G

        thanks. does it brick your phone if you root? and it know

        • Daggett Beaver

          No, it just pops up an error message when you boot after you root. You can just freeze 3 Knox apps, and you’ll never see the error message again.

  • Richard B

    This survey has no idea what softwares are on our phones- so it’s utter horseshit.

  • Daggett Beaver

    Read through the vulnerabilities. Most of the ones I browsed require either adb or an application be designed to exploit the vulnerability. While it has been demonstrated that some malware can sneak into the Play Store, none of the vulnerabilities I read about worry me in the least.

    • retrospooty

      Yup, another in a long line of yawn, my phone isnt secure articles.

      • Daggett Beaver

        Seriously… some of the vulnerabilities are camera overflow, kernel driver overflow… does anyone have any idea what is necessary to exploit these? And then what’s necessary to get your malware on the play store?

      • vikram

        [citation needed, again]
        (and then a contrasting one for iOS)

  • Grahaman27

    This chat is saying if a device isn’t getting an update that it is suddenly insecure… which is not true. this might as well be an update chart… yes we get it android needs better system for updates.

    look at 2013, it goes from 70% secure to 0% secure in a flash.

  • Pepi Dachev

    I’m running the latest Android 5.1.1 LMY48W on my Galaxy S4 I9505 which is the latest 5.1.1 and I think it’s secure.

  • Happy

    My phone is very secure – nailed and scotched to the wall….

  • Jack Silsan

    That’s a problem of being popular. Windows desktop users knows this better than anyone

    • Daggett Beaver

      Except that Windows vulnerabilities often involve just connecting your desktop to the Internet. None of the vulnerabilities I read about are anything like that (admittedly I didn’t read them all). They’re all “buffer overflow in the camera driver” stuff. So unless someone can find your phone’s IP address, connect to it, install an app without your knowledge and then use that app to start your camera… well, you can guess the rest.

    • vikram

      Fragmented? You do know that the distribution for iOS is:
      9.x is on 41%
      8.x on 40%
      7.x on 15%
      6.x on 3% of devices..
      (source: david-smith org)

      not to mention the different screen resolutions, aspects..

      5.x is on 23%
      4.x on 72.5%
      2.x on 4%..

      so tell me, who’s more fragmented?

