this post was submitted on 01 Oct 2023
69 points (93.7% liked)

Boost For Lemmy

6985 readers
5 users here now

Community of the Android app Boost for Lemmy Play Store Link

founded 1 year ago
MODERATORS
 

What version of libwebp does Boost use and if it is currently vulnerable, when can we expect an update to fix this issue? The affected versions of libwebp are 0.5.0 to 1.3.1.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] seaQueue@lemmy.world 11 points 11 months ago* (last edited 11 months ago) (6 children)

Depending on where the library lives in the Android ecosystem the update could be pushed by the play store framework as part of it's self-update capability or it could be pushed by the OEM with the next system OTA. If it's part of a system update you're at the mercy of the OEM's OTA schedule, Samsung hasn't pushed anything for my tablet in like 8mo, same for my OnePlus phone before the update this week.

Based on this discussion here (https://news.ycombinator.com/item?id=37658635) it sounds like we're all waiting for an OEM OTA, for some reason the video codecs are rolled into the play framework's updates but not the image decoding libraries.

People running LineageOS and other AOSP based firmwares should be covered after their ROMs integrate the next month security patch.

[โ€“] Prizephitah@feddit.nu 2 points 11 months ago (4 children)

So there is no central framework for pushing fixes to urgent fixes? Patching zero-days?

[โ€“] seaQueue@lemmy.world 4 points 11 months ago (3 children)

Welcome to the wonderful world of Android. They're rolled into the monthly AOSP security patch and end users are at the mercy of the OEM's update schedule.

This is why Pixel phone regular updates are a big deal, and a reason to run a regularly updated third party ROM like LineageOS.

[โ€“] Flyswat@lemmy.world 3 points 11 months ago

This is why Pixel phone regular updates are a big deal, and a reason to run a regularly updated third party ROM like LineageOS.

This is the very reason why I use LineageOS (as well as getting rid of bloatware).

load more comments (2 replies)
load more comments (2 replies)
load more comments (3 replies)