The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

  • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    18
    ·
    23 days ago

    In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.