Particle.news

Google Releases AndroidX Security State Libraries to Surface Component-Level Patch Status

The new libraries let apps and management tools check installed, published and available patch levels for system parts so they can decide when a device is safe for sensitive actions.

Overview

  • Google published stable AndroidX Security State v1.1.0 and Security State Provider v1.0.0 to provide a single API for reporting device patch posture.
  • The libraries expose three distinct patch levels—Device SPL (what is installed), Published SPL (what Google has published), and Available SPL (what the device can download)—for the system, system modules and the kernel.
  • A companion provider library defines a standard on-device IPC that lets OTA clients report update availability so third-party apps can query whether an update is staged for a specific device.
  • The libraries integrate Android Security Bulletin data and the Open Source Vulnerabilities database and honor Android 17 Supplemental Patches XML so apps can audit CVE-level fixes and recognize backported patches; kernel status is reported by LTS version number instead of a monthly date.
  • Google Play system updates and Google Over-The-Air already expose available patch levels, OEM adoption of the provider API is in progress, and Google has published docs, release notes and an issue tracker to help developers, MDMs and OEMs implement the new tools.