Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch)
Top notch camera, top specs, best software support. It’s usually my first choice when I look for an android phone.
A lot of the issues you listed are bad for people that want to mod their phones but they are pros for anyone that wants a secure phone. As I get older, I just want a phone that works that is actively supported and patched from security vulnerabilities.
It’s a bit hard to find the details of the vulnerabilities let alone POCs.
I would assume the APIs provided by android use the underlying system libraries so if left unpatched then any app that makes use of the APIs could potentially be an attack surface? This is all my assumption and it would be nice for someone that specialises in Android security to comment.
Well, the article already mentions a new free trade agreement with the EU and UK and an improved FTA with China.