| Considering that it's rare to get kernel (or any) updates on non-flagship phones, it seems likely. Backporting an old kernel should be possible, but the only indicator is the system update changelog that explicitly mentions it, I rarely see CVEs mentioned in changelogs on any smartphone. A tool to test the vulnerability is the only way. Any compromised app on the Play store or external can get root access instantly, but we can still rely on trust and audits when installing apps which should always be the rule. I suspect that this will be added to all Google Play integrity levels, limiting many apps from being installed on unpatched phones in the future. That's not the case with browsers with random sites and ads which is hardly avoidable, having any sandbox escape is now more severe considering that it bypasses the app container. It's similar to JailbreakMe on iOS [0] [0] https://en.wikipedia.org/wiki/JailbreakMe |
How the cluster f*k of the Android update situation Google has allowed this to happen really needs a regulator to step in.
Planned obsolescence is supposed to be illegal in Europe.