
It's common for Google to see smartphone vendors make changes to the Linux kernel in Android. It's a necessary action that must be done occasionally to ensure certain device drivers work properly. And those vendors include Samsung.
However says that the changes made to the Android kernel of the Samsung Galaxy A50 were not necessary. Horn is a member of Google's Project Zero (GPZ) team, which is responsible for finding bugs and security vulnerabilities.
The changes Samsung made to the kernel were intended to mitigate attacks, but Google says they ultimately created more security holes.
What did Samsung do that angered Google?
The smartphone maker added custom drivers to create direct hardware access to the Android Linux kernel. The problem is that Samsung made the changes without consulting the developers of the previous kernel.
In other words, Samsung tried to fix the problems on its own, which led to security holes in Galaxy running Android 9 and Android 10.
One such memory bug was fixed by Samsung in a security update in February, after Google reported it in November last year.
“I believe that kernel modifications related to this particular device would be better off either being upgraded or moved to user guides, where they can be implemented in safer programming languages and/or sandboxes and at the same time not complicate updates to newer kernel versions.”
Horn says that such additions to the kernel by a vendor often lead to vulnerabilities and force Google to take steps to secure it.
