Skip to content
You can now search across every topic, entity and event.What's new
Android
Technology

Android

Google's open-source mobile OS, ~72% of smartphones; EU-ordered to open 11 features to AI rivals.

Android, Google's mobile operating system with roughly 72% of global smartphones, was ordered by the European Commission on 16 July 2026 to open 11 features to rival AI providers.

Last refreshed: 26 July 2026 · Appears in 1 active topic

Key Question

How quickly does a CVE-2025-48595 Android patch actually reach most users' phones?

Timeline for Android

#13 15 Jul
#11 2 Jul
#6 2 Jun

Exposed versions 14, 15 and 16 to integer-overflow elevation-of-privilege exploitation

Cybersecurity: Threats and Defences: Old Linux container bug back in the wild
View full timeline →

Background

Android is the open-source mobile operating system developed by Google, built on the Linux kernel and licensed under Apache 2.0 and GPL. It is the world's most widely deployed mobile OS, running on an estimated 72 per cent of global smartphones across Google's own Pixel range and manufacturers including Samsung, Xiaomi and Oppo. Its architecture layers the Linux kernel, a hardware abstraction layer, the Android Runtime, and a Java-based Framework API managing app permissions and hardware access, with applications sandboxed via SELinux and an explicit-consent permission model.

Android's fragmentation across manufacturers and carriers means security-update timelines vary widely from Google's own Pixel reference track, despite a monthly Android Security Bulletin. That gap became concrete when CVE-2025-48595, an integer-overflow elevation-of-privilege flaw in the Android Framework affecting versions 14, 15 and 16, was added to CISA's Known Exploited Vulnerabilities catalogue on 2 June 2026 with a 5 June federal patch Deadline, a severity-8.4 flaw letting a malicious app silently take full device control.

That combination, a dominant but fragmented platform now also a named DMA gatekeeper surface, is why both its patch cadence and its interoperability obligations draw regulatory attention beyond ordinary product updates.

Key Issues
DMA enforcement

Android must open to AI rivals

On 16 July 2026 the European Commission adopted two Digital Markets Act specification decisions ordering Google to give third-party AI providers free, effective interoperability with 11 defined Android features, covering invocation, context access, on-device actions and hardware resources. Most changes must land in Android 18 by 1 August 2027, with hotword detection following in Android 19 by August 2028; each feature still needs explicit user consent.

The order arrived a week before the Commission's separate 890 million euro fine against Google over Search and Play Store Conduct, and days after Google exhausted its appeal against a 4.1 billion euro Android licensing fine dating to 2018. Android is now, alongside Search, the second front in Brussels' gatekeeper enforcement.

Common Questions
How do I check which Android security update my phone has installed?
Go to Settings, then About phone (or About device), then Android version or Security update. This shows the date of your most recent Android security patch. Compare it against the current month's Android Security Bulletin to see whether critical patches including CVE-2025-48595 have been applied.Source: Google Android documentation
Why do some Android phones get security updates slower than others?
Android's patch process goes from Google to device manufacturers (Samsung, Xiaomi, etc.) who must adapt the patch for their hardware variants, and then often to mobile carriers for network compatibility testing. This process can ADD weeks to months of delay beyond Google's Pixel reference timeline. Older devices may stop receiving patches entirely when manufacturers end support.Source: Android Open Source Project documentation, device manufacturer support policies
What Android versions are affected by CVE-2025-48595?
Android versions 14, 15 and 16 are affected. Android 13 and earlier are not in scope for this particular flaw. CISA confirmed active exploitation on 2 June 2026 and set a 5 June federal Deadline for agencies. Users on affected versions should apply the June 2026 Android security update immediately.Source: CISA KEV catalogue, Android Security Bulletin June 2026
What did the EU order Google to do with Android in July 2026?
The European Commission ordered Google to give third-party AI providers free interoperability with 11 defined Android features, mostly by Android 18 in August 2027.Source: European Commission, DMA Article 6(7) specification decision, 16 July 2026
How much of the smartphone market does Android have?
Android runs on an estimated 72 per cent of smartphones worldwide, across Google's own Pixel range and manufacturers such as Samsung, Xiaomi and Oppo.Source: StatCounter Global Stats
What is CVE-2025-48595?
An integer-overflow elevation-of-privilege flaw in the Android Framework affecting Android 14, 15 and 16, added to CISA's Known Exploited Vulnerabilities catalogue on 2 June 2026.Source: CISA, Known Exploited Vulnerabilities Catalog, 2 June 2026
When must Google comply with the EU's Android interoperability order?
Most of the 11 mandated features must be implemented by Android 18, no later than 1 August 2027; hotword detection follows in Android 19 by August 2028.Source: European Commission, DMA Article 6(7) specification decision, 16 July 2026
Source Material