The GrapheneOS team , the creator of the Android-based operating system of the same name, suggests that Android should introduce an automatic reboot feature to make it harder to exploit firmware flaws .
See also: Android: Tempting users to install the latest update

The project revealed that recently reported firmware vulnerabilities affecting Android devices , such as Google Pixel and Samsung Galaxy phones , could be exploited to steal data and spy on users when the device is not at rest.
When a device is in a “at rest” state, it means that it is either turned off or has not been unlocked since booting up. In this state, privacy protections are very high and the mobile device is not fully functional, as the encryption keys are not yet available for installed applications to use.
After rebooting, the first unlock causes multiple cryptographic keys to be transferred to the fast access memory so that installed applications work properly and the device enters a “non-idle” state.
The GrapheneOS team emphasizes that locking the screen after using the device does not return it to the “rest” state, as some secure exceptions remain active. Rebooting the device terminates all temporary states, processes, or activities that could be exploited and requires authentication such as a PIN, password, or biometric verification to unlock, thus reactivating all security mechanisms.
Although developers haven't shared many details about the exploited firmware bugs, they have suggested a general workaround that would work well in most cases: an automatic reboot feature that already exists in their operating system. The idea is to minimize the scope for attackers and interrupt existing object breaches by resetting all protections on the device more frequently than a user would .
See also: Android Auto: Discover how to personalize its UI
GrapheneOS's auto-reboot system resets the device every 72 hours, but as the OS's maker comments, this is a very long time and they plan to reduce it. GrapheneOS also notes that the flight modes on smartphones that many assume reduce the attack surface still allow data exchange over Wi-Fi, Bluetooth, NFC, and USB Ethernet, so depending on the attack vector, they may not be effective protection measures.

Developers address the issue of PIN/password security and their relationship to device encryption and security systems, as these authentication methods are used as keys to encrypt device data.
The limited functionality of the secure element is crucial for protecting short PINs and passphrases from de-privacy attacks that can unlock not only the screen but also the secure space on the device's built-in drive.
Frequent rebooting of your Android or iOS has been suggested as a good idea to fix issues like overheating, memory, or even call signal. From a security perspective, this action can protect against illegal data recovery or threats that lack effective evasion mechanisms.
GrapheneOS is an open source operating system focused on security and privacy. It provides a security-enhanced kernel with additional protections against attacks and breaches. GrapheneOS also includes an advanced application manager that allows users to fully control the permissions and capabilities of each application. This includes the ability to block applications from accessing specific data or system functions.
See also: How to install Android 14 beta on Google Pixel
With GrapheneOS, users can manage their device's power and performance, with the option to adjust power consumption and system performance to suit their needs. Finally, GrapheneOS provides built-in support for multiple user accounts, allowing users to maintain separate profiles for different uses of their device.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
