The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

you are viewing a single comment's thread
view the rest of the comments
[–] 34 points 1 day ago (1 child)

Google has reportedly declined the bug report

Yet another proof that preventing stores like F-droid is a good security choice /s

  • source
  • hideshow 1 child comment
  • In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.

  • source
  • parent